<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CiscoZine &#187; DOS</title>
	<atom:link href="http://www.ciscozine.com/tag/dos/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ciscozine.com</link>
	<description>Daily reporting on Cisco technology</description>
	<lastBuildDate>Tue, 13 Jul 2010 13:31:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>June 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 08:32:04 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=785</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:

Vulnerabilities in Cisco Unified Contact Center Express
Cisco Application Extension Platform Privilege Escalation Vulnerability

Vulnerabilities in Cisco Unified Contact Center Express
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p>The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:</p>
<ul>
<li>Vulnerabilities in Cisco Unified Contact Center Express</li>
<li>Cisco Application Extension Platform Privilege Escalation Vulnerability</li>
</ul>
<p><strong>Vulnerabilities in Cisco Unified Contact Center Express</strong><br />
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/">June 2010: two Cisco vulnerabilities</a> (623 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 11:32:32 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=778</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:

Multiple Vulnerabilities in Cisco PGW Softswitch
Multiple Vulnerabilities in Cisco Network Building Mediator


Multiple Vulnerabilities in Cisco PGW Softswitch
Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are [...]]]></description>
			<content:encoded><![CDATA[<p>The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:</p>
<ul>
<li>Multiple Vulnerabilities in Cisco PGW Softswitch</li>
<li>Multiple Vulnerabilities in Cisco Network Building Mediator</li>
</ul>
<p><strong><br />
Multiple Vulnerabilities in Cisco PGW Softswitch</strong><br />
Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages. (...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/">May 2010: two Cisco vulnerabilities</a> (480 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2010: seven more new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/03/30/march-2010-seven-more-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/03/30/march-2010-seven-more-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 16:09:12 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=769</guid>
		<description><![CDATA[On March 24 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published seven important vulnerability advisories:

Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Cisco Security Advisory: Cisco IOS Software H.323 Denial of Service Vulnerabilities
Cisco Security Advisory: Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability
Cisco Security Advisory: Cisco IOS [...]]]></description>
			<content:encoded><![CDATA[<p>On March 24 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published seven important vulnerability advisories:</p>
<ul>
<li>Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</li>
<li>Cisco Security Advisory: Cisco IOS Software H.323 Denial of Service Vulnerabilities</li>
<li>Cisco Security Advisory: Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability</li>
<li>Cisco Security Advisory: Cisco IOS Software IPsec Vulnerability</li>
<li>Cisco Security Advisory: Cisco IOS Software NAT Skinny Call Control Protocol Vulnerability</li>
<li>Cisco Security Advisory: Cisco Unified Communications Manager Express Denial of Service Vulnerabilities</li>
<li>Cisco Security Advisory: Cisco IOS Software Crafted TCP Packet Denial of Service Vulnerability</li>
</ul>
<p><strong>(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/03/30/march-2010-seven-more-new-cisco-vulnerabilities/">March 2010: seven more new Cisco vulnerabilities</a> (1,964 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/03/30/march-2010-seven-more-new-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/03/30/march-2010-seven-more-new-cisco-vulnerabilities/#comments">One comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/03/30/march-2010-seven-more-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>March 2010: three new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 08:45:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=766</guid>
		<description><![CDATA[On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories:

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
Cisco Digital Media Manager Vulerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
A vulnerability exists in the Cisco Digital Media [...]]]></description>
			<content:encoded><![CDATA[<p>On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories:</p>
<ul>
<li>Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability</li>
<li>Cisco Digital Media Manager Vulerabilities</li>
<li>Cisco Unified Communications Manager Denial of Service Vulnerabilities</li>
</ul>
<p><strong>Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability<br />
</strong>A vulnerability exists in the Cisco Digital Media Player that could allow an unauthenticated attacker to inject video or data content into a remote display.</p>
<p><strong>Vulnerable Products<br />
</strong>Cisco Digital Media Player versions earlier than 5.2 are affected by this vulnerability.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/">March 2010: three new Cisco vulnerabilities</a> (400 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/inject-data/" rel="tag">Inject data</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2010: four new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 11:15:59 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=762</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories.
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities:

TCP Connection Exhaustion Denial of Service Vulnerability
Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities
Skinny Client Control Protocol (SCCP) [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories.</p>
<p><strong>Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</strong><br />
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities:</p>
<ul>
<li>TCP Connection Exhaustion Denial of Service Vulnerability</li>
<li>Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities</li>
<li>Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability</li>
<li>WebVPN Datagram Transport Layer Security (DTLS) Denial of Service Vulnerability</li>
<li>Crafted TCP Segment Denial of Service Vulnerability</li>
<li>Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability</li>
<li>NT LAN Manager version 1 (NTLMv1) Authentication Bypass Vulnerability</li>
</ul>
<p>These vulnerabilities are not interdependent; a release that is affected by one vulnerability is not necessarily affected by the others. There are workarounds for some of the vulnerabilities disclosed in this advisory.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/">February 2010: four new Cisco vulnerabilities</a> (1,191 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/</link>
		<comments>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 22:04:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=759</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories.
Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities:

Insufficient validation of SQL commands
Unauthorized account creation
User and password enumeration in Cisco MeetingTime
Privilege escalation in Cisco MeetingTime

(...)Read the rest of [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories.</p>
<p><strong>Multiple Vulnerabilities in Cisco Unified MeetingPlace</strong><br />
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities:</p>
<ul>
<li>Insufficient validation of SQL commands</li>
<li>Unauthorized account creation</li>
<li>User and password enumeration in Cisco MeetingTime</li>
<li>Privilege escalation in Cisco MeetingTime</li>
</ul>
<p><strong>(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/">3 new Cisco critical vulnerabilities</a> (762 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple Cisco WebEx WRF Player Vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 09:44:26 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[WebEx]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=754</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory:  Multiple Cisco WebEx WRF Player Vulnerabilities.
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) Player. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system of a targeted [...]]]></description>
			<content:encoded><![CDATA[<p>The The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory:  Multiple Cisco WebEx WRF Player Vulnerabilities.</p>
<p>Multiple buffer <strong>overflow</strong> vulnerabilities exist in the <strong>Cisco WebEx Recording Format (WRF) Player</strong>. In some cases, exploitation of the vulnerabilities could allow a remote attacker to <strong>execute arbitrary code</strong> on the system of a targeted user.</p>
<p>The Cisco WebEx WRF Player is an application that is used to play back WebEx meeting recordings that have been recorded on the computer of an on-line meeting attendee. The WRF Player can be automatically installed when the user accesses a WRF file that is hosted on a WebEx server. The WRF Player can also be manually installed for offline playback after downloading the application from <a href="http://www.webex.com" target="_blank">www.webex.com</a>.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/">Multiple Cisco WebEx WRF Player Vulnerabilities</a> (429 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a>, <a href="http://www.ciscozine.com/tag/webex/" rel="tag">WebEx</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Unified Presence Denial of Service Vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/10/20/cisco-unified-presence-denial-of-service-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/10/20/cisco-unified-presence-denial-of-service-vulnerabilities/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 19:14:40 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=736</guid>
		<description><![CDATA[On Octobert 14, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisories: Cisco Unified Presence Denial of Service Vulnerabilities.
Cisco Unified Presence contains two denial of service (DoS) vulnerabilities that may cause an interruption to presence services. These vulnerabilities were discovered internally by Cisco, and there are no workarounds.
Vulnerable [...]]]></description>
			<content:encoded><![CDATA[<p>On Octobert 14, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisories: Cisco Unified Presence Denial of Service Vulnerabilities.</p>
<p>Cisco Unified Presence contains <strong>two denial of service</strong> (DoS) vulnerabilities that may cause an interruption to presence services. These vulnerabilities were discovered internally by Cisco, and there are no workarounds.</p>
<p><strong>Vulnerable Products</strong><br />
The following products are affected:</p>
<ul>
<li>Cisco Unified Presence 1.x versions</li>
<li>Cisco Unified Presence 6.x versions prior to 6.0(6)</li>
<li>Cisco Unified Presence 7.x versions prior to 7.0(4)</li>
</ul>
<p>(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/10/20/cisco-unified-presence-denial-of-service-vulnerabilities/">Cisco Unified Presence Denial of Service Vulnerabilities</a> (226 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/10/20/cisco-unified-presence-denial-of-service-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/10/20/cisco-unified-presence-denial-of-service-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/10/20/cisco-unified-presence-denial-of-service-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sep.23, 2009: 11 new Cisco critical vulnerabilities!!</title>
		<link>http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 10:00:44 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=733</guid>
		<description><![CDATA[On September 23, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 11 important vulnerability advisories.
Cisco Unified Communications Manager Express Vulnerability
Cisco IOS® devices that are configured for Cisco Unified Communications Manager Express (CME) and the Extension Mobility feature are vulnerable to a buffer overflow vulnerability. Successful exploitation of this vulnerability may result [...]]]></description>
			<content:encoded><![CDATA[<p>On September 23, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 11 important vulnerability advisories.</p>
<p><strong>Cisco Unified Communications Manager Express Vulnerability</strong><br />
Cisco IOS® devices that are configured for Cisco Unified Communications Manager Express (CME) and the Extension Mobility feature are vulnerable to a buffer overflow vulnerability. Successful exploitation of this vulnerability may result in the execution of arbitrary code or a Denial of Service (DoS) condition on an affected device.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/">Sep.23, 2009: 11 new Cisco critical vulnerabilities!!</a> (2,112 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products</title>
		<link>http://www.ciscozine.com/2009/09/18/tcp-state-manipulation-denial-of-service-vulnerabilities-in-multiple-cisco-products/</link>
		<comments>http://www.ciscozine.com/2009/09/18/tcp-state-manipulation-denial-of-service-vulnerabilities-in-multiple-cisco-products/#comments</comments>
		<pubDate>Fri, 18 Sep 2009 16:29:03 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=732</guid>
		<description><![CDATA[On September 8, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisories: TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products.
Multiple Cisco products are affected by denial of service (DoS) vulnerabilities that manipulate the state of Transmission Control Protocol (TCP) connections. By manipulating the state of [...]]]></description>
			<content:encoded><![CDATA[<p>On September 8, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisories: TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products.</p>
<p>Multiple Cisco products are affected by denial of service (DoS) vulnerabilities that manipulate the state of Transmission Control Protocol (TCP) connections. By manipulating the state of a TCP connection, an attacker could force the TCP connection to remain in a long-lived state, possibly indefinitely. If enough TCP connections are forced into a long-lived or indefinite state, resources on a system under attack may be consumed, preventing new TCP connections from being accepted. In some cases, a system reboot may be necessary to recover normal system operation. To exploit these vulnerabilities, an attacker must be able to complete a TCP three-way handshake with a vulnerable system.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/09/18/tcp-state-manipulation-denial-of-service-vulnerabilities-in-multiple-cisco-products/">TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products</a> (297 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/09/18/tcp-state-manipulation-denial-of-service-vulnerabilities-in-multiple-cisco-products/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/09/18/tcp-state-manipulation-denial-of-service-vulnerabilities-in-multiple-cisco-products/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/09/18/tcp-state-manipulation-denial-of-service-vulnerabilities-in-multiple-cisco-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
