Show filters
169 Total Results
Displaying 121-130 of 169
Sort by:
Attacker Value
Unknown

CVE-2009-0470

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.
0
Attacker Value
Unknown

CVE-2009-0471

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the hostname command with a level/15/configure/-/hostname request.
0
Attacker Value
Unknown

CVE-2008-3821

Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.
0
Attacker Value
Unknown

CVE-2008-4609

Disclosure Date: October 20, 2008 (last updated October 04, 2023)
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
0
Attacker Value
Unknown

CVE-2008-3798

Disclosure Date: September 26, 2008 (last updated October 04, 2023)
Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, properly formed SSL packet that occurs during termination of an SSL session.
0
Attacker Value
Unknown

CVE-2008-3809

Disclosure Date: September 26, 2008 (last updated October 04, 2023)
Cisco IOS 12.0 through 12.4 on Gigabit Switch Router (GSR) devices (aka 12000 Series routers) allows remote attackers to cause a denial of service (device crash) via a malformed Protocol Independent Multicast (PIM) packet.
0
Attacker Value
Unknown

CVE-2008-3810

Disclosure Date: September 26, 2008 (last updated October 04, 2023)
Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka CSCsg22426, a different vulnerability than CVE-2008-3811.
0
Attacker Value
Unknown

CVE-2008-3804

Disclosure Date: September 26, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Multi Protocol Label Switching (MPLS) Forwarding Infrastructure (MFI) in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (memory corruption) via crafted packets for which the software path is used.
0
Attacker Value
Unknown

CVE-2008-3808

Disclosure Date: September 26, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted Protocol Independent Multicast (PIM) packet.
0
Attacker Value
Unknown

CVE-2008-3799

Disclosure Date: September 26, 2008 (last updated October 04, 2023)
Memory leak in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (memory consumption and voice-service outage) via unspecified valid SIP messages.
0