CVE-2007-1258
- EPSS 0.56%
- Published 03.03.2007 20:19:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial...
CVE-2007-0917
- EPSS 0.66%
- Published 14.02.2007 02:28:00
- Last modified 09.04.2025 00:30:58
The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.
CVE-2007-0918
- EPSS 2.29%
- Published 14.02.2007 02:28:00
- Last modified 09.04.2025 00:30:58
The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations tha...
CVE-2007-0648
- EPSS 2.33%
- Published 01.02.2007 01:28:00
- Last modified 09.04.2025 00:30:58
Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.
- EPSS 1.42%
- Published 11.01.2007 11:28:00
- Last modified 09.04.2025 00:30:58
The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."
- EPSS 3.39%
- Published 23.09.2006 10:07:00
- Last modified 03.04.2025 01:03:51
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOC...
CVE-2006-4650
- EPSS 0.64%
- Published 09.09.2006 00:04:00
- Last modified 03.04.2025 01:03:51
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect ...
- EPSS 4.28%
- Published 27.07.2006 22:04:00
- Last modified 03.04.2025 01:03:51
Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the sess...
CVE-2006-0485
- EPSS 0.14%
- Published 01.02.2006 02:02:00
- Last modified 03.04.2025 01:03:51
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allo...
CVE-2006-0486
- EPSS 0.1%
- Published 01.02.2006 02:02:00
- Last modified 03.04.2025 01:03:51
Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user d...