Latest CVE Feed
-
8.6
HIGHCVE-2018-0378
A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devic... Read more
Affected Products : nx-os nx-os nexus_5548p nexus_5548up nexus_5596up nexus_5596t nexus_56128p nexus_5672up nexus_6001 nexus_6004 +4 more products- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0377
A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote attacker to directly connect to the OSGi interface. The vulnerability is due to a lack of authentication. An... Read more
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0376
A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit thi... Read more
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0375
A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credentials. The vulnerability is due to the ... Read more
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0374
A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directly to the Policy Builder database. The vulnerability is due to a lack of authentication. An attacker could ... Read more
Affected Products : mobility_services_engine- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0373
A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected ... Read more
- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0372
A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which could result in a ... Read more
Affected Products : nx-os nexus_92160yc-x nexus_92304qc nexus_9236c nexus_9272q nexus_93108tc-ex nexus_93120tx nexus_93128tx nexus_93180yc-ex nexus_9332pq +10 more products- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-0371
A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of incoming HTTP requests. An attacker could... Read more
Affected Products : meeting_server- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0369
A vulnerability in the reassembly logic for fragmented IPv4 packets of Cisco StarOS running on virtual platforms could allow an unauthenticated, remote attacker to trigger a reload of the npusim process, resulting in a denial of service (DoS) condition. T... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0368
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient security restrictions imposed by the affected s... Read more
Affected Products : application_policy_infrastructure_controller_enterprise_module- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0367
A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affecte... Read more
Affected Products : registered_envelope_service- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0366
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an... Read more
Affected Products : web_security_appliance- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0364
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.... Read more
Affected Products : unified_communications_domain_manager- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0363
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary... Read more
Affected Products : unified_communications_manager_im_and_presence_service- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2018-0362
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute action... Read more
Affected Products : 5400_enterprise_network_compute_system_firmware 5100_enterprise_network_compute_system_firmware ucs-e160s-m3_firmware ucs-e160s-k9_firmware ucs-e180d-m3_firmware ucs-e180d-k9_firmware ucs-e1120d-m3_firmware ucs-e1120d-k9_firmware ucs-e140s-m2_firmware ucs-e140s-k9_firmware +32 more products- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0361
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0360
ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0359
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier, aka Session Fixation. The vulne... Read more
Affected Products : meeting_server- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0358
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to exhaustion of file ... Read more
Affected Products : telepresence_video_communication_server- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0357
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input ... Read more
Affected Products : webex_meetings- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024