CVE-2014-3289
- EPSS 0.66%
- Veröffentlicht 10.06.2014 11:19:35
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 an...
CVE-2014-2119
- EPSS 1.37%
- Veröffentlicht 21.03.2014 01:04:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 ...
- EPSS 0.62%
- Veröffentlicht 27.06.2013 21:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email Security Appliance devices before 7.1.5-104, 7.3 before 7.3.2-026, 7.5 before 7.5.2-203, and 7.6 bef...
CVE-2013-3385
- EPSS 0.55%
- Veröffentlicht 27.06.2013 21:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3...
CVE-2013-3386
- EPSS 0.39%
- Veröffentlicht 27.06.2013 21:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IronPort Spam Quarantine (ISQ) component in the web framework in IronPort AsyncOS on Cisco Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019 and Content Security Management Appliance devices before 7.9.1-102...
- EPSS 0.75%
- Veröffentlicht 27.06.2013 21:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL sen...
CVE-2009-1162
- EPSS 0.52%
- Veröffentlicht 05.06.2009 16:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter.