Latest CVE Feed
-
9.0
HIGHCVE-2015-0721
Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via cra... Read more
Affected Products : nx-os nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nx-os nexus_5010 nexus_5020 nexus_5548p nexus_5548up nexus_5596up +47 more products- EPSS Score: %0.14
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6392
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) sm... Read more
Affected Products : nx-os nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nx-os nexus_5010 nexus_5020 nexus_5548p nexus_5548up nexus_5596up +31 more products- EPSS Score: %1.34
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7020
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- EPSS Score: %3.86
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6426
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web ... Read more
- EPSS Score: %0.24
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6423
The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.... Read more
Affected Products : ios- EPSS Score: %0.44
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-6421
Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID CSCvb05643.... Read more
Affected Products : ios_xr- EPSS Score: %0.55
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6393
The AAA service in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.1 through 3.18 and 16.2 allows remote attackers to cause a denial of service (device reload) via a failed SSH connection attempt that is mishandled during generation of an e... Read more
- EPSS Score: %8.65
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6391
Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036.... Read more
Affected Products : ios- EPSS Score: %0.74
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6385
Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.... Read more
- EPSS Score: %3.57
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2016-6380
The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DN... Read more
- EPSS Score: %2.26
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6379
Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089.... Read more
- EPSS Score: %0.74
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6378
Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets that require NAT, aka Bug ID CSCuw85853.... Read more
- EPSS Score: %0.74
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1455
Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CSCuz05365.... Read more
Affected Products : nx-os nx-os nexus_93128 nexus_9396px nexus_9396tx nexus_9504 nexus_9508 nexus_9516 nexus_n9336pq- EPSS Score: %0.68
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-6418
Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552.... Read more
Affected Products : videoscape_distribution_suite_service_manager- EPSS Score: %0.29
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-6417
Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.13
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-6416
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to ca... Read more
Affected Products : web_security_appliance email_security_appliance content_security_management_appliance- EPSS Score: %0.89
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6392
Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.... Read more
- EPSS Score: %1.03
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6386
Cisco IOS XE 3.1 through 3.17 and 16.1 on 64-bit platforms allows remote attackers to cause a denial of service (data-structure corruption and device reload) via fragmented IPv4 packets, aka Bug ID CSCux66005.... Read more
- EPSS Score: %0.74
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6384
Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device reload) via crafted fields in an H.323 message, aka Bug ID CSCux04257.... Read more
- EPSS Score: %1.97
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6382
Cisco IOS 15.2 through 15.6 and IOS XE 3.6 through 3.17 and 16.1 allow remote attackers to cause a denial of service (device restart) via a malformed IPv6 Protocol Independent Multicast (PIM) register packet, aka Bug ID CSCuy16399.... Read more
- EPSS Score: %6.26
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025