CVEs (50)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Email Security Appliance May 6, 2026 Oct 28, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click...Show more |
1Cisco 3Content Security Management Appliance Email Security ApplianceWeb Security ApplianceMay 6, 2026 Oct 5, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) de...Show more |
2Cisco Clamav3Clamav Email Security ApplianceWeb Security ApplianceMay 6, 2026 Jun 8, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x...Show more |
1Cisco 3Content Security Management Appliance Email Security ApplianceWeb Security ApplianceMay 6, 2026 Nov 6, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5...Show more |
Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment...Show more |
1Cisco 2Email Security Appliance Email Security Appliance FirmwareMay 6, 2026 Oct 2, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211...Show more |
Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP reques...Show more |
1Cisco 3Content Security Management Appliance Email Security ApplianceWeb Security ApplianceMay 6, 2026 Jul 29, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL...Show more |
1Cisco 2Email Security Appliance Email Security Appliance FirmwareMay 6, 2026 Jul 10, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via...Show more |
The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCu...Show more |