Vulnerabilities (CVE)

Filtered by vendor Cisco Subscribe
Total 6077 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0157 1 Cisco 2 Ios, Pix Firewall Software 2023-12-10 5.0 MEDIUM N/A
Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.
CVE-2003-0512 1 Cisco 1 Ios 2023-12-10 5.0 MEDIUM N/A
Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
CVE-1999-0063 1 Cisco 1 Ios 2023-12-10 5.0 MEDIUM N/A
Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
CVE-2001-0455 1 Cisco 1 Aironet 340 2023-12-10 7.5 HIGH N/A
Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.
CVE-2000-0613 1 Cisco 1 Pix Firewall 2023-12-10 5.0 MEDIUM N/A
Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.
CVE-2001-0753 1 Cisco 1 Cbos 2023-12-10 7.5 HIGH N/A
Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges.
CVE-1999-0158 1 Cisco 1 Pix Firewall Software 2023-12-10 5.0 MEDIUM N/A
Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.
CVE-2001-0752 1 Cisco 1 Cbos 2023-12-10 5.0 MEDIUM N/A
Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set.
CVE-2002-2315 1 Cisco 1 Ios 2023-12-10 7.8 HIGH N/A
Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router.
CVE-2001-0861 1 Cisco 1 12000 Router 2023-12-10 5.0 MEDIUM N/A
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.
CVE-1999-0160 1 Cisco 1 Ios 2023-12-10 7.5 HIGH N/A
Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.
CVE-2001-0621 1 Cisco 1 Content Services Switch 11000 2023-12-10 7.5 HIGH N/A
The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.
CVE-1999-0734 1 Cisco 1 Ciscosecure 2023-12-10 7.5 HIGH N/A
A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.
CVE-2004-0308 1 Cisco 1 Optical Networking Systems Software 2023-12-10 10.0 HIGH N/A
Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.
CVE-2002-1097 1 Cisco 2 Vpn 3000 Concentrator Series Software, Vpn 3002 Hardware Client 2023-12-10 7.5 HIGH N/A
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
CVE-2003-1004 1 Cisco 2 Pix Firewall, Pix Firewall Software 2023-12-10 5.0 MEDIUM N/A
Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall.
CVE-2002-1108 1 Cisco 1 Vpn Client 2023-12-10 5.0 MEDIUM N/A
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.
CVE-2002-1357 7 Cisco, Fissh, Intersoft and 4 more 7 Ios, Ssh Client, Securenetterm and 4 more 2023-12-10 10.0 HIGH N/A
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
CVE-2002-1556 1 Cisco 1 Optical Networking Systems Software 2023-12-10 5.0 MEDIUM N/A
Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR).
CVE-2002-2053 1 Cisco 1 Ios 2023-12-10 5.0 MEDIUM N/A
The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop.