Vulnerabilities > Cisco > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-08-22 | CVE-2016-6361 | Improper Input Validation vulnerability in Cisco Aironet Access Point Software The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via a crafted AMPDU header, aka Bug ID CSCuz56288. | 6.1 |
2016-08-22 | CVE-2016-6359 | Cross-site Scripting vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug IDs CSCva40650 and CSCva40817. | 4.3 |
2016-08-22 | CVE-2016-1485 | Cross-site Scripting vulnerability in Cisco Identity Services Engine Software 1.3(0.876) Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva46497. | 4.3 |
2016-08-08 | CVE-2016-1474 | Improper Access Control vulnerability in Cisco Prime Infrastructure 2.2(2) Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuw65846, a different vulnerability than CVE-2015-6434. | 4.3 |
2016-08-08 | CVE-2016-1468 | OS Command Injection vulnerability in Cisco Telepresence Video Communication Server X8.5.2 The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531. | 6.5 |
2016-08-01 | CVE-2016-1461 | Improper Input Validation vulnerability in Cisco Asyncos Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932. | 5.0 |
2016-07-28 | CVE-2016-1467 | Resource Management Errors vulnerability in Cisco Videoscape Session Resource Manager Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813. | 6.1 |
2016-07-28 | CVE-2016-1465 | Resource Management Errors vulnerability in Cisco Nx-Os Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985. | 6.1 |
2016-07-28 | CVE-2016-1463 | Improper Input Validation vulnerability in Cisco Firesight System Software Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737. | 5.0 |
2016-07-28 | CVE-2016-1462 | Cross-site Scripting vulnerability in Cisco Prime Service Catalog 11.0Base Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795. | 4.3 |