Latest CVE Feed
-
6.5
MEDIUMCVE-2016-6435
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.... Read more
- EPSS Score: %55.03
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6434
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.... Read more
- EPSS Score: %0.38
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-6433
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.... Read more
- EPSS Score: %72.60
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6428
Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.... Read more
Affected Products : ios_xr- EPSS Score: %0.08
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-6427
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, a... Read more
- EPSS Score: %0.13
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-6425
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL,... Read more
- EPSS Score: %0.30
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6424
The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942.... Read more
- EPSS Score: %0.68
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6422
Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles certain operators, flags, and keywords in TCAM share ACLs, which allows remote attackers to bypass intended access restrictions by sending packets that sho... Read more
Affected Products : ios- EPSS Score: %0.21
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-6027
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify da... Read more
Affected Products : sterling_secure_proxy- EPSS Score: %0.24
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-6026
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.... Read more
Affected Products : sterling_secure_proxy- EPSS Score: %0.07
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-6025
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involvi... Read more
Affected Products : sterling_secure_proxy- EPSS Score: %0.20
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6023
Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to read arbitrary files via a crafted URL.... Read more
Affected Products : sterling_secure_proxy- EPSS Score: %0.22
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-1454
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP... Read more
Affected Products : nx-os nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nx-os nexus_5010 nexus_5020 nexus_3048 nexus_3548 nexus_6001 +45 more products- EPSS Score: %1.40
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1453
Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long parameters in a packet header, aka Bug ID CSCuy95701.... Read more
- EPSS Score: %26.08
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6393
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via malformed IPv4 DHCP packets to the DHCPv4 relay agent... Read more
Affected Products : nx-os nx-os nexus_5010 nexus_5020 nexus_5548p nexus_5548up nexus_5596up nexus_5596t nexus_56128p nexus_5672up +21 more products- EPSS Score: %0.99
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-0721
Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via cra... Read more
Affected Products : nx-os nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nx-os nexus_5010 nexus_5020 nexus_5548p nexus_5548up nexus_5596up +47 more products- EPSS Score: %0.14
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6392
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) sm... Read more
Affected Products : nx-os nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nx-os nexus_5010 nexus_5020 nexus_5548p nexus_5548up nexus_5596up +31 more products- EPSS Score: %1.34
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7020
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- EPSS Score: %3.86
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6426
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web ... Read more
- EPSS Score: %0.24
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6423
The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.... Read more
Affected Products : ios- EPSS Score: %0.44
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025