
CVE-2017-3830
https://notcve.org/view.php?id=CVE-2017-3830
22 Feb 2017 — A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected appliance. More Information: CSCvc89678. Known Affected Releases: 2.1. Known Fixed Releases: 2.1.2. Una vulnerabilidad en una API interna de Cisco Meeting Server (CMS) podría permitir a un atacante remoto no autenticado provocar una condición de denegación de servicio (DoS) en la aplicación afectada. • http://www.securityfocus.com/bid/96242 • CWE-20: Improper Input Validation •

CVE-2017-3837
https://notcve.org/view.php?id=CVE-2017-3837
22 Feb 2017 — An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. In addition, the attacker could potentially cause the application to crash unexpectedly, resulting in a denial of service (DoS) condition. The attacker would need to be authenticated and have a valid session with the Web Bridge. Affec... • http://www.securityfocus.com/bid/96243 • CWE-20: Improper Input Validation •

CVE-2017-3823 – Cisco WebEx Chrome Extension Remote Command Execution
https://notcve.org/view.php?id=CVE-2017-3823
01 Feb 2017 — An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on ... • https://packetstorm.news/files/id/140870 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-3799
https://notcve.org/view.php?id=CVE-2017-3799
26 Jan 2017 — A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1. Una vulnerabilidad en un parámetro URL de Cisco WebEx Meeting Center podría permitir a un atacante remoto no autenticado realizar redirección de sitio. Más información: CSCzu78401. • http://www.securityfocus.com/bid/95642 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2016-9218
https://notcve.org/view.php?id=CVE-2016-9218
26 Jan 2017 — A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releases: 1.0. Una vulnerabilidad en Cisco Hybrid Meeting Server podría permitir a un atacante remoto no autenticado llevar a cabo un ataque de CSRF contra el usuario de la interfaz web. Más información: CSCvc28662. • http://www.securityfocus.com/bid/95634 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2016-6447
https://notcve.org/view.php?id=CVE-2016-6447
03 Nov 2016 — A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to 2.0.1, Acano Server releases prior to 1.8.16 and prior to 1.9.3, Cisco Meeting App releases prior to 1.9.8, Acano Meeting Apps releases prior to 1.8.35. More Information: CSCva75942 CSCvb67878. Known Affected Releases: 1.81.92.0. Una vulnerabilidad en Cisco Meeting Ser... • http://www.securityfocus.com/bid/94073 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-6448
https://notcve.org/view.php?id=CVE-2016-6448
03 Nov 2016 — A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0. Una vulnerabilidad en el analizador de Session ... • http://www.securityfocus.com/bid/94076 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-6444
https://notcve.org/view.php?id=CVE-2016-6444
27 Oct 2016 — A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. Una vulnerabilidad en Cisco Meeting Server podría permitir a un atacante remoto no autenticado llevar a cabo un ataque de CSRF contra un usuario Web Bridge. Más información: CSCvb03308. • http://www.securityfocus.com/bid/93785 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2016-6445
https://notcve.org/view.php?id=CVE-2016-6445
27 Oct 2016 — A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user. This vulnerability is due to the XMPP service incorrectly processing a deprecated authentication scheme. A successful exploit could allow an attacker to access the system as another user. Una vulnerabilidad en el servicio Extensible Messaging y P... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-msc • CWE-20: Improper Input Validation •

CVE-2016-6446
https://notcve.org/view.php?id=CVE-2016-6446
27 Oct 2016 — A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. Una vulnerabilidad en Web Bridge for Cisco Meeting Server podría permitir a un atacante remoto no autenticado recuperar memoria de un servidor conectado. Más información: CSCvb03308. • http://www.securityfocus.com/bid/93782 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •