Show filters
91 Total Results
Displaying 41-50 of 91
Sort by:
Attacker Value
Unknown

CVE-2007-4291

Disclosure Date: August 09, 2007 (last updated October 04, 2023)
Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998; a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unregistration and (3) CSCsg70474; and a malformed Real-time Transport Protocol (RTP) packet, which causes a device crash, as identified by (4) CSCse68138, related to VOIP RTP Lib, and (5) CSCse05642, related to I/O memory corruption.
0
Attacker Value
Unknown

CVE-2007-4295

Disclosure Date: August 09, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80749.
0
Attacker Value
Unknown

CVE-2007-4286

Disclosure Date: August 09, 2007 (last updated October 04, 2023)
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.
0
Attacker Value
Unknown

CVE-2007-2813

Disclosure Date: May 22, 2007 (last updated October 04, 2023)
Cisco IOS 12.4 and earlier, when using the crypto packages and SSL support is enabled, allows remote attackers to cause a denial of service via a malformed (1) ClientHello, (2) ChangeCipherSpec, or (3) Finished message during an SSL session.
0
Attacker Value
Unknown

CVE-2007-2688

Disclosure Date: May 16, 2007 (last updated October 04, 2023)
The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
0
Attacker Value
Unknown

CVE-2007-2586

Disclosure Date: May 10, 2007 (last updated October 04, 2023)
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
0
Attacker Value
Unknown

CVE-2007-0480

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.
0
Attacker Value
Unknown

CVE-2007-0479

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.
0
Attacker Value
Unknown

CVE-2007-0481

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.
0
Attacker Value
Unknown

CVE-2006-4650

Disclosure Date: September 09, 2006 (last updated October 04, 2023)
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs.
0