Show filters
100 Total Results
Displaying 81-90 of 100
Sort by:
Attacker Value
Unknown

CVE-2007-6567

Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action.
0
Attacker Value
Unknown

CVE-2007-5381

Disclosure Date: October 12, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.
0
Attacker Value
Unknown

CVE-2007-0480

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.
0
Attacker Value
Unknown

CVE-2007-0479

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.
0
Attacker Value
Unknown

CVE-2007-0481

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.
0
Attacker Value
Unknown

CVE-2006-4950

Disclosure Date: September 23, 2006 (last updated October 04, 2023)
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.
0
Attacker Value
Unknown

CVE-2006-1060

Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.
0
Attacker Value
Unknown

CVE-2006-0485

Disclosure Date: February 01, 2006 (last updated February 22, 2025)
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.
0
Attacker Value
Unknown

CVE-2006-0340

Disclosure Date: January 21, 2006 (last updated February 22, 2025)
Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.
0
Attacker Value
Unknown

CVE-2005-3921

Disclosure Date: November 30, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.
0