CVE-2012-3088
- EPSS 0.48%
- Published 16.09.2012 10:34:50
- Last modified 11.04.2025 00:51:21
Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCu...
- EPSS 0.14%
- Published 06.08.2012 17:55:01
- Last modified 11.04.2025 00:51:21
Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate during WebLaunch of IPsec, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz...
CVE-2012-2499
- EPSS 0.14%
- Published 06.08.2012 17:55:01
- Last modified 11.04.2025 00:51:21
The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSC...
- EPSS 0.1%
- Published 06.08.2012 17:55:01
- Last modified 11.04.2025 00:51:21
Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSC...
CVE-2012-1370
- EPSS 0.47%
- Published 06.08.2012 15:55:01
- Last modified 11.04.2025 00:51:21
Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.
CVE-2012-2496
- EPSS 1.11%
- Published 20.06.2012 20:55:02
- Last modified 11.04.2025 00:51:21
A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR7 on 64-bit Linux platforms does not properly restrict use of Java components, which allows remote attacke...
CVE-2012-2495
- EPSS 0.22%
- Published 20.06.2012 20:55:02
- Last modified 11.04.2025 00:51:21
The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remo...
CVE-2012-2494
- EPSS 0.2%
- Published 20.06.2012 20:55:02
- Last modified 11.04.2025 00:51:21
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows re...
CVE-2012-2493
- EPSS 1.58%
- Published 20.06.2012 20:55:02
- Last modified 11.04.2025 00:51:21
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2.5 MR6 and 3.x before 3.0 MR8 on Mac OS X and Linux, does not properly validate binaries that are rec...
CVE-2011-2041
- EPSS 0.07%
- Published 02.06.2011 20:55:03
- Last modified 11.04.2025 00:51:21
The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction,...