Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:o:cisco:ios:15.2:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2013-1143 |
The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory access and device reload) via a traffic engineering PATH message in an RSVP packet, aka Bug ID CSCtg39957. Published: March 28, 2013; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 7.1 HIGH |
CVE-2013-1142 |
Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745. Published: March 28, 2013; 7:55:01 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2012-4623 |
The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723. Published: September 26, 2012; 8:55:01 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2012-4621 |
The Device Sensor feature in Cisco IOS 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via a DHCP packet, aka Bug ID CSCty96049. Published: September 26, 2012; 8:55:01 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2012-4620 |
Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via tunneled (1) GRE/IP, (2) IPIP, or (3) IPv6 in IPv4 packets, aka Bug ID CSCts66808. Published: September 26, 2012; 8:55:01 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2012-4619 |
The NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtr46123. Published: September 26, 2012; 8:55:00 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2012-4618 |
The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183. Published: September 26, 2012; 8:55:00 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2012-4617 |
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914. Published: September 26, 2012; 8:55:00 PM -0400 |
V3.x:(not available) V2.0: 7.1 HIGH |
CVE-2012-3950 |
The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, aka Bug ID CSCtw55976. Published: September 26, 2012; 8:55:00 PM -0400 |
V3.x:(not available) V2.0: 7.1 HIGH |
CVE-2012-3949 |
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664. Published: September 26, 2012; 8:55:00 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2012-3924 |
The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCty97961. Published: September 16, 2012; 6:34:51 AM -0400 |
V3.x:(not available) V2.0: 3.5 LOW |
CVE-2012-3923 |
The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827. Published: September 16, 2012; 6:34:51 AM -0400 |
V3.x:(not available) V2.0: 3.5 LOW |
CVE-2012-3915 |
The DMVPN tunnel implementation in Cisco IOS 15.2 allows remote attackers to cause a denial of service (persistent IKE state) via a large volume of hub-to-spoke traffic, aka Bug ID CSCtq39602. Published: September 16, 2012; 6:34:51 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2012-3895 |
Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224. Published: September 16, 2012; 6:34:50 AM -0400 |
V3.x:(not available) V2.0: 6.3 MEDIUM |
CVE-2012-3893 |
The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke traffic, aka Bug ID CSCtz02622. Published: September 16, 2012; 6:34:50 AM -0400 |
V3.x:(not available) V2.0: 6.3 MEDIUM |
CVE-2012-1361 |
Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750. Published: August 06, 2012; 2:55:01 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2012-1344 |
Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328. Published: August 06, 2012; 2:55:00 PM -0400 |
V3.x:(not available) V2.0: 3.5 LOW |
CVE-2012-1367 |
The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCAL_PREF) attribute length, aka Bug ID CSCtq06538. Published: August 06, 2012; 11:55:01 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2012-1324 |
Race condition in the Zone-Based Firewall in Cisco IOS 15.1 and 15.2, when IPS policies are configured, allows remote attackers to cause a denial of service (device crash) by sending IPv6 packets, aka Bug ID CSCtk53534. Published: May 03, 2012; 4:55:03 PM -0400 |
V3.x:(not available) V2.0: 7.1 HIGH |
CVE-2011-4231 |
Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128. Published: May 03, 2012; 6:11:39 AM -0400 |
V3.x:(not available) V2.0: 6.3 MEDIUM |