|
212481
|
9.8 |
CRITICAL
Network
|
cisco
|
firepower_extensible_operating_system unified_computing_system
|
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows r…
|
CWE-78
OS Command
|
CVE-2015-6435
|
2024-11-21 11:34 |
2016-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212482
|
9.8 |
CRITICAL
Network
|
cisco
|
modular_encoding_platform_d9036_software
|
Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug …
|
CWE-255
Credentials Management
|
CVE-2015-6412
|
2024-11-21 11:34 |
2016-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212483
|
4.3 |
MEDIUM
Network
|
cisco
|
adaptive_security_appliance_software
|
The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitra…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6423
|
2024-11-21 11:34 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212484
|
7.3 |
HIGH
Network
|
cisco
|
aironet_access_point_software
|
Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vect…
|
CWE-255
Credentials Management
|
CVE-2015-6336
|
2024-11-21 11:34 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212485
|
9.8 |
CRITICAL
Network
|
cisco
|
identity_services_engine_software
|
The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrativ…
|
NVD-CWE-noinfo
|
CVE-2015-6323
|
2024-11-21 11:34 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212486
|
7.5 |
HIGH
Network
|
cisco
|
aironet_access_point_software
|
The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of service via a crafted header in an IP packet, aka Bug …
|
CWE-399
Resource Management Errors
|
CVE-2015-6320
|
2024-11-21 11:34 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212487
|
9.8 |
CRITICAL
Network
|
cisco
|
wireless_lan_controller_software
|
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bu…
|
CWE-287
Improper Authentication
|
CVE-2015-6314
|
2024-11-21 11:34 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212488
|
6.1 |
MEDIUM
Network
|
microsoft
|
sharepoint_foundation sharepoint_server
|
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6117
|
2024-11-21 11:34 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212489
|
6.1 |
MEDIUM
Network
|
cisco
|
prime_infrastructure
|
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted we…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6434
|
2024-11-21 11:34 |
2016-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212490
|
6.5 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767.
|
CWE-89
SQL Injection
|
CVE-2015-6433
|
2024-11-21 11:34 |
2016-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|