Cisco
cisco
6,669 CVEs • 6,229 products
Products (6,229)
Click to collapseToggle
Products (6,229)
Click to collapse
CVEs (6,669)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 29, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote attackers to caus...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 29, 2011 N/A· v4 N/A· v3 7.1 HIGH· v2 The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to us...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 29, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x does not properly handle idle TCP connections, which allows remote attackers to cause a denial of service (memory co...Show more |
1Cisco 2Unified Communications Manager Unified Presence ServerApr 29, 2026 Aug 29, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Presence Server 6.x, 7.x, 8.0, and 8.5 before 8.5xnr allow remote attacker...Show more |
Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and le...Show more |
Cisco IOS 12.2(58)SE, when a login banner is configured, allows remote attackers to cause a denial of service (device reload) by establishing two SSH2 sessions, aka Bug ID CSCto62631. |
1Cisco 3Asr 9006 Router Asr 9010 RouterIos XrApr 29, 2026 Jul 28, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 Unspecified vulnerability in Cisco IOS XR 4.1.x before 4.1.1 on Cisco Aggregation Services Routers (ASR) 9000 series devices allows remote attackers to cause a denial of service (line-card reload) via an IPv4 packet, aka...Show more |
1Cisco 4Sa500 Software Sa520Sa520w+1 moreApr 29, 2026 Jul 28, 2011 N/A· v4 N/A· v3 9.0 HIGH· v2 The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CS...Show more |
1Cisco 4Sa500 Software Sa520Sa520w+1 moreApr 29, 2026 Jul 28, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 SQL injection vulnerability in the web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote attackers to execute arbitrary SQL commands via unspecified vectors,...Show more |
1Cisco 2Content Services Gateway Second Generation IosApr 29, 2026 Jul 11, 2011 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco IOS 12.4MDA before 12.4(24)MDA5 on the Cisco Content Services Gateway - Second Generation (CSG2) allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets, aka Bug ID CSCtl79577. |
The Cisco VPN Client 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms uses weak permissions (NT AUTHORITY\INTERACTIVE:F) for cvpnd.exe, which allows local users to gain privileges by replacing this executable file w...Show more |
The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote attackers to bypass the Router Advertisement Guarding functionality via a fragmented IPv6 packet in which the Router...Show more |
1Cisco 1Anyconnect Secure Mobility Client Apr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 7.2 HIGH· v2 The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecifi...Show more |
Cisco Network Registrar before 7.2 has a default administrative password, which makes it easier for remote attackers to obtain access via a TCP session, aka Bug ID CSCsm50627. |
1Cisco 15Skinny Client Control Protocol Software Unified Ip Phone 7906Unified Ip Phone 7911g+12 moreApr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 1.5 LOW· v2 Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn659...Show more |
1Cisco 2Media Experience Engine 5600 Media Processing SoftwareApr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 Cisco Media Processing Software before 1.2 on Media Experience Engine (MXE) 5600 devices has a default root password, which makes it easier for context-dependent attackers to obtain access via (1) the local console, (2)...Show more |
1Cisco 15Skinny Client Control Protocol Software Unified Ip Phone 7906Unified Ip Phone 7911g+12 moreApr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 6.6 MEDIUM· v2 Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bug ID CSCtn65815. |
1Cisco 15Skinny Client Control Protocol Software Unified Ip Phone 7906Unified Ip Phone 7911g+12 moreApr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 6.6 MEDIUM· v2 The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecified vectors, aka Bug ID CSCtf07426. |
1Cisco 1Anyconnect Secure Mobility Client Apr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linux and Mac OS X downloads a client executable file (vpndownloader.exe) w...Show more |
1Cisco 1Anyconnect Secure Mobility Client Apr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 7.6 HIGH· v2 The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifyin...Show more |