Latest CVE Feed
-
7.1
HIGHCVE-2018-0469
A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a double-free-in-memory handling by the affected software when specific H... Read more
Affected Products : ios_xe- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0468
A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, local attacker to access and alter confidential data. The vulnerability is due to the installation of the ... Read more
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0467
A vulnerability in the IPv6 processing code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect handling of specific IPv6 hop-by-hop options. An attacker cou... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0466
A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. The vulnerability is due to incorrect handling of s... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0465
A vulnerability in the web-based management interface of Cisco Small Business 300 Series Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected system.... Read more
Affected Products : sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware sf300-24mp_firmware +44 more products- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-0464
A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system. The vulnerability is due to improper validation o... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0463
A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to gain unauthorized access to configuration data that is stored on an affected NSO system. Th... Read more
Affected Products : network_services_orchestrator- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-0462
A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a denial of service (DoS) attack against an affected system. The vulnerability is due to ... Read more
Affected Products : enterprise_network_virtualization_software enterprise_nfv_infrastructure_software- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0461
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the software running on an affected device i... Read more
- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-0460
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation c... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-0459
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0458
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected... Read more
Affected Products : prime_collaboration_assurance- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0457
A vulnerability in the Cisco Webex Player for Webex Recording Format (WRF) files could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by sending a user a link or email a... Read more
Affected Products : webex_meetings_online- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2018-0456
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application of an affected device to restart unexpectedly. The vulnerability is... Read more
Affected Products : nx-os- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0455
A vulnerability in the Server Message Block Version 2 (SMBv2) and Version 3 (SMBv3) protocol implementation for the Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the device to run low on system memory, possibly p... Read more
Affected Products : firepower_system_software- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0454
A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to perform command injection. The vulnerability is due to insufficient input validation of command input. An attacker... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2018-0453
A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0452
A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. T... Read more
Affected Products : tetration_analytics- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0451
A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability i... Read more
Affected Products : tetration_analytics- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0450
A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the management interface on an affected device. The... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024