Page 28 of 430 results (0.012 seconds)

CVSS: 9.8EPSS: 1%CPEs: 5EXPL: 0

28 Sep 2009 — Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779. Desbordamiento de búfer en la implementación del inicio de sesión de la característica "Extension Mobility" del componente "Unified Communications Manager Express" (CME) de Cisco IOS v12.4XW, v12... • http://osvdb.org/58335 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 8.1EPSS: 0%CPEs: 136EXPL: 0

28 Sep 2009 — Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227. Una condición de carrera en la función Firewall Authentication Proxy de Cisco IOS v12.0 hasta la v12.4 permite a atacantes remotos evitar la autenticación, o saltarse la página web de la autorización, a través de una solicitud debidamente modificada. Se trata del Bug ID CSCsy15227. • http://osvdb.org/58340 • CWE-287: Improper Authentication •

CVSS: 9.1EPSS: 0%CPEs: 7EXPL: 0

28 Sep 2009 — The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CSCsw47076, CSCsv48603, CSCsy54122, and CSCsu50252. Los "Object Groups" (grupos de objetos) para la funcionalidad de listas de control de acceso (ACLs) en Cisco IOS v12.2XNB, v12.2XNC, v12.2XND, v12.4MD, v12.4T, v12.4XZ y v12.4YA permiten a los usuarios remot... • http://osvdb.org/58338 •

CVSS: 7.8EPSS: 0%CPEs: 19EXPL: 0

28 Sep 2009 — Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880. Vulnerabilidad sin especificar en Cisco IOS v12.2 hasta la v12.4. Cuando la función "Cisco Unified Border Element" esta activada, permite a usuarios remotos provocar una denegación de servicio (recarga del dispositivo) a través de mensajes SIP modificados. También conocido como... • http://tools.cisco.com/security/center/viewAlert.x?alertId=18891 •

CVSS: 7.8EPSS: 2%CPEs: 72EXPL: 0

28 Sep 2009 — Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104. Vulnerabilidad sin especificar en Cisco IOS v12.2 hasta la v12.4 permite a usuarios remotos provocar una denegación de servicio (recarga del dispositivo) a través de un paquete H.323 modificado. También conocido como Bug ID CSCsz38104. • http://osvdb.org/58337 •

CVSS: 7.8EPSS: 2%CPEs: 10EXPL: 0

28 Sep 2009 — Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948. Vulnerabilidad sin especificar en Cisco IOS v12.2XNA, v12.2XNB, v12.2XNC, v12.2XND, v12.4MD, v12.4T, v12.4XZ y v12.4YA permite a usuarios remotos provocar una denegación de servicio (recarga del dispositivo) a través de un paquete NTPv4 modificado. También conocido c... • http://osvdb.org/58342 •

CVSS: 7.5EPSS: 0%CPEs: 288EXPL: 0

28 Sep 2009 — Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel, aka Bug IDs CSCsh97579 and CSCsq31776. Cisco IOS v12.0 hasta la v12.4, cuando están activados los túneles basados en IP y la utilidad "Cisco Express Forwarding", permite a atacantes remotos provocar una denegación de servicio (recarg... • http://osvdb.org/58333 •

CVSS: 7.5EPSS: 2%CPEs: 304EXPL: 0

28 Sep 2009 — Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via malformed packets, aka Bug ID CSCsx70889. Cisco IOS v12.0 hasta 12.4, cuando está habilitada la funcionalidad de túnel basado en IP y el Cisco Express Forwarding, permite a atacantes remotos provocar una denegación de servicio (reinicio del dispositivo) mediante paquetes deformados, también conocido como Bug ID CSCsx70889. • http://osvdb.org/58334 •

CVSS: 7.8EPSS: 1%CPEs: 6EXPL: 0

27 Aug 2009 — Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987. Cisco Unified Communications Manager (también con... • http://osvdb.org/57453 •

CVSS: 7.5EPSS: 2%CPEs: 15EXPL: 0

30 Jul 2009 — Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (memory corruption and device reload) by using an RFC4271 peer to send an update with a long series of AS numbers, aka Bug ID CSCsy86021. Cisco IOS v12.0(32)S12 hasta v12.... • http://secunia.com/advisories/36046 • CWE-399: Resource Management Errors •