Skip to main content

Vendor/product archive

cisco / ios CVEs

Beta · best-effort

602 CVEs tagged to cisco / ios32 Critical, 323 High, 236 Medium, 11 Low, 0 Unrated.

CVE-2006-0486

Published Feb 1, 2006

Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login ses…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0340

Published Jan 21, 2006

Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote atta…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4826

Published Dec 31, 2005

Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (dev…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3921

Published Nov 30, 2005

Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML tha…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-3481

Published Nov 3, 2005

Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffer overflow in system timers. NOTE: this issue does not correspond to a specific…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-2841

Published Sep 8, 2005

Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to caus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2451

Published Aug 3, 2005

Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2105

Published Jul 5, 2005

Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0195

Published May 2, 2005

Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0196

Published May 2, 2005

Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malfor…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0197

Published May 2, 2005

Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reloa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1020

Published May 2, 2005

Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1021

Published May 2, 2005

Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through 12.3, when authenticating against a TACACS+ server, allows remote attackers to cause a denial of service (memory consum…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1057

Published May 2, 2005

Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1058

Published May 2, 2005

Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0186

Published Jan 19, 2005

Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1111

Published Jan 10, 2005

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP pack…

CVSS 5.0 · Medium

CVE-2004-1454

Published Dec 31, 2004

Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1464

Published Dec 31, 2004

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or rev…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2004-1775

Published Dec 31, 2004

Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuratio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0244

Published Nov 23, 2004

Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset)…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 602 CVEsPage 22 of 25