← Back

Cisco

cisco

6,590 CVEs • 6,223 products

Products (6,223)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,590)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Unified Presence
Unified Presence Server
Apr 23, 2026
May 16, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via malformed packets, aka Bug ID CSCsh50164.
1Cisco
2Cisco Content Switching Module
Cisco Content Switching Module Ssl
Apr 23, 2026
May 14, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Memory leak in Cisco Content Switching Module (CSM) 4.2(3) up to 4.2(8) and Cisco Content Switching Module with SSL (CSM-S) 2.1(2) up to 2.1(7) allows remote attackers to cause a denial of service (memory consumption) vi...Show more
Memory leak in Cisco Content Switching Module (CSM) 4.2(3) up to 4.2(8) and Cisco Content Switching Module with SSL (CSM-S) 2.1(2) up to 2.1(7) allows remote attackers to cause a denial of service (memory consumption) via TCP segments with an unspecified combination of TCP flags.Show less
1Cisco
1Network Admission Control
Apr 23, 2026
Apr 16, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Acce...Show more
Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Access Manager (CAM) by sniffing error logs.Show less
1Cisco
4Emergency Responder
Mobility ManagerUnified Communications Manager+1 more
Apr 23, 2026
Apr 4, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobili...Show more
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.Show less
1Cisco
2Cisco Ios
Ios
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 pack...Show more
The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.Show less
1Cisco
1Ios
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
Memory leak in the virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (memory consumption) via a series of PPTP sessions, related to "dead memor...Show more
Memory leak in the virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (memory consumption) via a series of PPTP sessions, related to "dead memory" that remains allocated after process termination, aka bug ID CSCsj58566.Show less
1Cisco
1Ios
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
The virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (resource exhaustion) via a series of PPTP sessions, related to the persistence of interf...Show more
The virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (resource exhaustion) via a series of PPTP sessions, related to the persistence of interface descriptor block (IDB) data structures after process termination, aka bug ID CSCdv59309.Show less
1Cisco
2Cisco Ios
Ios
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast states on the core routers" via a crafte...Show more
Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast states on the core routers" via a crafted Multicast Distribution Tree (MDT) Data Join message.Show less
1Cisco
2Cisco Ios
Ios
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to...Show more
Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.Show less
1Cisco
2Route Switch Processor
Supervisor Engine
Apr 23, 2026
Mar 27, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and...Show more
Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device restart, or memory leak) via unknown vectors.Show less
1Cisco
1Ciscoworks Internetwork Performance Monitor
Apr 23, 2026
Mar 14, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitrary commands.
1Cisco
3Acs For Windows
Acs Solution EngineUser Changeable Password
Apr 23, 2026
Mar 14, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote...Show more
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.Show less
1Cisco
3Acs For Windows
Acs Solution EngineUser Changeable Password
Apr 23, 2026
Mar 14, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbi...Show more
Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.Show less
1Cisco
1Pix Asa Finesse Operation System
Apr 23, 2026
Mar 10, 2008
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspac...Show more
The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. NOTE: third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blankShow less
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response.
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data.
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request.
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet.