Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-12-14 CVE-2016-9205 Resource Management Errors vulnerability in Cisco IOS XR 6.1.1
A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-399
7.5
2016-12-14 CVE-2016-9203 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco ASR 5000 Series Software 20.0.2.3.65026
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an unauthenticated, remote attacker to cause a reload of the ipsecmgr process.
network
low complexity
cisco CWE-119
7.5
2016-12-14 CVE-2016-9201 Improper Input Validation vulnerability in Cisco IOS 15.3(3)M3
A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass traffic that should otherwise have been dropped based on the configuration.
network
low complexity
cisco CWE-20
7.5
2016-12-14 CVE-2016-9198 Resource Management Errors vulnerability in Cisco Identity Services Engine 1.2(1.199)
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack.
network
low complexity
cisco CWE-399
7.5
2016-12-14 CVE-2016-9193 Improper Input Validation vulnerability in Cisco products
A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system.
network
low complexity
cisco CWE-20
7.5
2016-12-14 CVE-2016-9192 Permissions, Privileges, and Access Controls vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account.
local
low complexity
cisco CWE-264
7.8
2016-12-14 CVE-2016-6474 Improper Authentication vulnerability in Cisco IOS 15.5(2.25)T
A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on an affected system.
network
low complexity
cisco CWE-287
7.3
2016-12-14 CVE-2016-6470 Permissions, Privileges, and Access Controls vulnerability in Cisco Hybrid Media Service 1.0Base
A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to the root level.
local
low complexity
cisco CWE-264
7.8
2016-12-14 CVE-2016-6469 Resource Management Errors vulnerability in Cisco web Security Appliance 9.0.1162/9.1.1074
A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) vulnerability due to the proxy process unexpectedly restarting.
network
low complexity
cisco CWE-399
7.5
2016-12-14 CVE-2016-6468 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Emergency Responder 11.5(1.10000.4)
A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.8