Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-04-21 CVE-2006-1960 Cross-Site Scripting vulnerability in Cisco Wireless Lan Solution Engine ArchiveApplyDisplay.JSP
Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.
network
cisco
5.8
2006-04-20 CVE-2006-1928 Denial of Service vulnerability in Cisco IOS XR MPLS
Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or "MPLS packet handling problems") via certain MPLS packets, as identified by Cisco bug IDs (1) CSCsd15970 and (2) CSCsd55531.
network
low complexity
cisco
5.0
2006-04-20 CVE-2006-1927 Denial of Service vulnerability in Cisco IOS XR MPLS
Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attackers to cause a denial of service (Line card crash) via certain MPLS packets, as identified by Cisco bug ID CSCsc77475.
network
low complexity
cisco
5.0
2006-04-07 CVE-2006-1671 Multiple vulnerability in Cisco Optical Networking System and Transport Controller
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSCsc51390; (2) a "crafted" IP packet to a device with IP on the LAN interface, aka bug ID CSCsd04168; and (3) a "malformed" OSPF packet, aka bug ID CSCsc54558.
network
low complexity
cisco
5.0
2006-04-05 CVE-2006-1631 Remote Denial of Service vulnerability in Cisco 11500 Content Services Switch HTTP Compression
Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests.
network
low complexity
cisco
5.0
2006-02-18 CVE-2006-0764 Products TACACS+ Authentication Bypass vulnerability in Cisco products
The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows remote attackers to bypass authentication and gain privileges, aka Bug ID CSCsd21455.
network
high complexity
cisco
5.1
2006-02-01 CVE-2006-0486 Local Security vulnerability in Cisco IOS 12.2(25)S/12.3T/12.4
Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770.
local
low complexity
cisco
4.6
2006-02-01 CVE-2006-0485 Unspecified vulnerability in Cisco IOS
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.
local
low complexity
cisco
4.6
2006-01-22 CVE-2006-0367 Remote Privilege Escalation vulnerability in Cisco CallManager CCMAdmin
Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."
network
low complexity
cisco
6.5
2006-01-22 CVE-2006-0354 Resource Management Errors vulnerability in Cisco products
Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644.
low complexity
cisco CWE-399
5.5