Entries Tagged ‘Privilege escalation’

June 2010: two Cisco vulnerabilities

The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:

Vulnerabilities in Cisco Unified Contact Center Express
Cisco Application Extension Platform Privilege Escalation Vulnerability

Vulnerabilities in Cisco Unified Contact Center Express
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities [...]

May 2010: two Cisco vulnerabilities

The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:

Multiple Vulnerabilities in Cisco PGW Softswitch
Multiple Vulnerabilities in Cisco Network Building Mediator

Multiple Vulnerabilities in Cisco PGW Softswitch
Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are [...]

March 2010: three new Cisco vulnerabilities

On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories:

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
Cisco Digital Media Manager Vulerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
A vulnerability exists in the Cisco Digital Media [...]

February 2010: four new Cisco vulnerabilities

Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories.
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities:

TCP Connection Exhaustion Denial of Service Vulnerability
Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities
Skinny Client Control Protocol (SCCP) [...]

3 new Cisco critical vulnerabilities

Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories.
Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities:

Insufficient validation of SQL commands
Unauthorized account creation
User and password enumeration in Cisco MeetingTime
Privilege escalation in Cisco MeetingTime

Vulnerabilities in Unified Contact Center Express Administration Pages

Reported to Cisco by National Australia Bank’s Security Assurance team, on July 15, 2009 the PSIRT has published a new security advisory concerning to vulnerabilities in Unified Contact Center Express Administration Pages.
Cisco Unified Contact Center Express (Cisco Unified CCX) server contains both a directory traversal vulnerability and a script injection vulnerability in the administration pages [...]

Jun.24, 2009: 2 new Cisco critical vulnerabilities

On June 24, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 2 new vulnerability advisories.
1) Cisco Physical Access Gateway Denial of Service Vulnerability
A denial of service (DoS) vulnerability exists in the Cisco Physical Access Gateway. There are no workarounds available to mitigate the vulnerability. This vulnerability has been corrected in Cisco [...]

Mar.25, 2009?! 8 new Cisco vulnerability advisories!

On March 25, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 8 new vulnerability advisories. Mainly these vulnerabilities are DOS attack.
 
1) Cisco IOS cTCP Denial of Service Vulnerability
A series of TCP packets may cause a denial of service (DoS) condition on Cisco IOS devices that are configured as Easy VPN servers [...]

2 new Cisco critical vulnerabilities

On 4 March 2009 and on 11 March 2009, Cisco has published two new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.
1) Cisco 7600 Series Router Session Border Controller Denial of Service Vulnerability
A denial of service (DoS) vulnerability exists in the Cisco Session Border Controller (SBC) for [...]

3 new Cisco critical vulnerabilities

On 25 February 2009, Cisco has published three new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.
1) Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine
The Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application [...]