Show filters
246 Total Results
Displaying 201-210 of 246
Sort by:
Attacker Value
Unknown
CVE-2012-0384
Disclosure Date: March 29, 2012 (last updated November 24, 2024)
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.
0
Attacker Value
Unknown
CVE-2012-0382
Disclosure Date: March 29, 2012 (last updated October 04, 2023)
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.
0
Attacker Value
Unknown
CVE-2012-0381
Disclosure Date: March 29, 2012 (last updated October 04, 2023)
The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.
0
Attacker Value
Unknown
CVE-2011-4046
Disclosure Date: November 12, 2011 (last updated October 04, 2023)
The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code.
0
Attacker Value
Unknown
CVE-2011-4047
Disclosure Date: November 12, 2011 (last updated October 04, 2023)
The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.
0
Attacker Value
Unknown
CVE-2011-4048
Disclosure Date: November 12, 2011 (last updated October 04, 2023)
The Dell KACE K2000 System Deployment Appliance has a default username and password for the read-only reporting account, which makes it easier for remote attackers to obtain sensitive information from the database by leveraging the default credentials.
0
Attacker Value
Unknown
CVE-2011-4436
Disclosure Date: November 12, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-2395
Disclosure Date: June 09, 2011 (last updated October 04, 2023)
The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote attackers to bypass the Router Advertisement Guarding functionality via a fragmented IPv6 packet in which the Router Advertisement (RA) message is contained in the second fragment, as demonstrated by (1) a packet in which the first fragment contains a long Destination Options extension header or (2) a packet in which the first fragment contains an ICMPv6 Echo Request message.
0
Attacker Value
Unknown
CVE-2011-1672
Disclosure Date: April 10, 2011 (last updated October 04, 2023)
The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password.
0
Attacker Value
Unknown
CVE-2010-3201
Disclosure Date: January 07, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.
0