CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93246  CVE-2016-6426  Candidate  The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.  Assigned (20160726)  None (candidate not yet proposed)    View
93247  CVE-2016-6427  Candidate  Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.  Assigned (20160726)  None (candidate not yet proposed)    View
93248  CVE-2016-6428  Candidate  Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.  Assigned (20160726)  None (candidate not yet proposed)    View
93249  CVE-2016-6429  Candidate  A vulnerability in the web framework code of the Cisco IP Interoperability and Collaboration System (IPICS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. More Information: CSCva47092. Known Affected Releases: 4.10(1).  Assigned (20160726)  None (candidate not yet proposed)    View
93250  CVE-2016-6430  Candidate  A vulnerability in the command-line interface of the Cisco IP Interoperability and Collaboration System (IPICS) could allow an authenticated, local attacker to elevate the privilege level associated with their session. More Information: CSCva38636. Known Affected Releases: 4.10(1). Known Fixed Releases: 5.0(1).  Assigned (20160726)  None (candidate not yet proposed)    View

Page 18650 of 20943, showing 5 records out of 104715 total, starting on record 93246, ending on 93250

Actions