Cisco

Ios

504 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.81%
  • Veröffentlicht 14.02.2007 02:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations tha...

  • EPSS 2.33%
  • Veröffentlicht 01.02.2007 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.

  • EPSS 1.42%
  • Veröffentlicht 11.01.2007 11:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."

  • EPSS 3.32%
  • Veröffentlicht 23.09.2006 10:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOC...

  • EPSS 0.64%
  • Veröffentlicht 09.09.2006 00:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect ...

  • EPSS 4.28%
  • Veröffentlicht 27.07.2006 22:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the sess...

  • EPSS 0.14%
  • Veröffentlicht 01.02.2006 02:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allo...

  • EPSS 0.1%
  • Veröffentlicht 01.02.2006 02:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user d...

  • EPSS 3.02%
  • Veröffentlicht 21.01.2006 00:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang an...

Exploit
  • EPSS 1.6%
  • Veröffentlicht 30.11.2005 11:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memor...