| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2012-3895 |
Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224. Published: September 16, 2012; 6:34:50 AM -0400 |
V3.x:(not available) V2.0: 6.3 MEDIUM |
| CVE-2012-3893 |
The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke traffic, aka Bug ID CSCtz02622. Published: September 16, 2012; 6:34:50 AM -0400 |
V3.x:(not available) V2.0: 6.3 MEDIUM |
| CVE-2012-3079 |
Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957. Published: September 16, 2012; 6:34:50 AM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
| CVE-2012-1361 |
Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750. Published: August 06, 2012; 2:55:01 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2012-1350 |
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426. Published: August 06, 2012; 2:55:00 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
| CVE-2012-1344 |
Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328. Published: August 06, 2012; 2:55:00 PM -0400 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2012-1338 |
Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users to cause a denial of service (device reload) by completing local web authentication quickly, aka Bug ID CSCts88664. Published: August 06, 2012; 1:55:00 PM -0400 |
V3.x:(not available) V2.0: 6.3 MEDIUM |
| CVE-2012-1367 |
The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCAL_PREF) attribute length, aka Bug ID CSCtq06538. Published: August 06, 2012; 11:55:01 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2012-1327 |
dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (assertion failure and reboot) via 802.11 wireless traffic, as demonstrated by a video call from Apple iOS 5.0 on an iPhone 4S, aka Bug ID CSCtt94391. Published: May 03, 2012; 4:55:03 PM -0400 |
V3.x:(not available) V2.0: 6.1 MEDIUM |
| CVE-2012-1324 |
Race condition in the Zone-Based Firewall in Cisco IOS 15.1 and 15.2, when IPS policies are configured, allows remote attackers to cause a denial of service (device crash) by sending IPv6 packets, aka Bug ID CSCtk53534. Published: May 03, 2012; 4:55:03 PM -0400 |
V3.x:(not available) V2.0: 7.1 HIGH |
| CVE-2011-4231 |
Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128. Published: May 03, 2012; 6:11:39 AM -0400 |
V3.x:(not available) V2.0: 6.3 MEDIUM |
| CVE-2011-4019 |
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883. Published: May 03, 2012; 6:11:39 AM -0400 |
V3.x:(not available) V2.0: 5.4 MEDIUM |
| CVE-2012-0362 |
The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bug ID CSCts01106. Published: May 02, 2012; 6:09:22 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2012-0339 |
Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID CSCsi77774. Published: May 02, 2012; 6:09:22 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2012-0338 |
Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish SSH connections from arbitrary source IP addresses via a standard SSH client, aka Bug ID CSCsv86113. Published: May 02, 2012; 6:09:22 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2011-4016 |
The PPP implementation in Cisco IOS 12.2 and 15.0 through 15.2, when Point-to-Point Termination and Aggregation (PTA) and L2TP are used, allows remote attackers to cause a denial of service (device crash) via crafted network traffic, aka Bug ID CSCtf71673. Published: May 02, 2012; 6:09:21 AM -0400 |
V3.x:(not available) V2.0: 5.4 MEDIUM |
| CVE-2011-4015 |
Cisco IOS 15.2S allows remote attackers to cause a denial of service (interface queue wedge) via malformed UDP traffic on port 465, aka Bug ID CSCts48300. Published: May 02, 2012; 6:09:21 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2011-4012 |
Cisco IOS 12.0, 15.0, and 15.1, when a Policy Feature Card 3C (PFC3C) is used, does not create a fragment entry during processing of an ICMPv6 ACL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtj90091. Published: May 02, 2012; 6:09:21 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
| CVE-2011-4007 |
Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka Bug ID CSCtr56576. Published: May 02, 2012; 6:09:21 AM -0400 |
V3.x:(not available) V2.0: 5.4 MEDIUM |
| CVE-2011-3289 |
Cisco IOS 12.4 and 15.0 through 15.2 allows physically proximate attackers to bypass the No Service Password-Recovery feature and read the start-up configuration via unspecified vectors, aka Bug ID CSCtr97640. Published: May 02, 2012; 6:09:21 AM -0400 |
V3.x:(not available) V2.0: 3.6 LOW |