CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93231  CVE-2016-6411  Candidate  Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.  Assigned (20160726)  None (candidate not yet proposed)    View
93232  CVE-2016-6412  Candidate  The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.  Assigned (20160726)  None (candidate not yet proposed)    View
93233  CVE-2016-6413  Candidate  The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.  Assigned (20160726)  None (candidate not yet proposed)    View
93234  CVE-2016-6414  Candidate  iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.  Assigned (20160726)  None (candidate not yet proposed)    View
93235  CVE-2016-6415  Candidate  The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.  Assigned (20160726)  None (candidate not yet proposed)    View

Page 18647 of 20943, showing 5 records out of 104715 total, starting on record 93231, ending on 93235

Actions