|
265591
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_contact_center_enterprise
|
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a cr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1439
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265592
|
7.5 |
HIGH
Network
|
cisco
|
asyncos
|
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.
|
CWE-20 CWE-254
Improper Input Validation 7PK - Security Features
|
CVE-2016-1438
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265593
|
6.5 |
MEDIUM
Network
|
cisco
|
prime_collaboration_deployment
|
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID…
|
CWE-89
SQL Injection
|
CVE-2016-1437
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265594
|
7.5 |
HIGH
Network
|
cisco
|
asr_5000_software
|
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1436
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265595
|
7.0 |
HIGH
Local
|
cisco
|
ip_phone_8800_series_firmware
|
Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1435
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265596
|
6.5 |
MEDIUM
Network
|
cisco
|
ip_phone_8800_series_firmware
|
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.
|
CWE-22 CWE-20
Path Traversal Improper Input Validation
|
CVE-2016-1434
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265597
|
6.5 |
MEDIUM
Network
|
cisco
|
ios_xe
|
Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug…
|
CWE-399 NVD-CWE-Other
Resource Management Errors
|
CVE-2016-1428
|
2024-11-21 11:46 |
2016-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265598
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
ios
|
Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun63132.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1424
|
2024-11-21 11:46 |
2016-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265599
|
6.5 |
MEDIUM
Network
|
cisco
|
rv215w_wireless-n_vpn_router_firmware rv110w_wireless-n_vpn_firewall_firmware rv130w_wireless-n_multifunction_vpn_router_firmware
|
Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1397
|
2024-11-21 11:46 |
2016-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265600
|
6.1 |
MEDIUM
Network
|
cisco
|
rv130w_wireless-n_multifunction_vpn_router_firmware rv110w_wireless-n_vpn_firewall_firmware rv215w_wireless-n_vpn_router_firmware
|
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices w…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1396
|
2024-11-21 11:46 |
2016-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|