Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cisco ironport email security appliances vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2014-8016
The Cisco IronPort Email Security Appliance (ESA) allows remote malicious users to cause a denial of service (CPU consumption) via long Subject headers in e-mail messages, aka Bug ID CSCzv93864.
Cisco Ironport Email Security Appliances
4.3
CVSSv2
CVE-2009-1162
Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS prior to 6.5.2 on Series C, M, and X appliances allows remote malicious users to inject arbitrary web script or HTML via the referrer parameter.
Cisco Ironport Asyncos 6.0.0-754
Cisco Ironport Asyncos 6.0.0-757
Cisco Ironport Asyncos 6.1.0-301
Cisco Ironport Asyncos 6.1.0-304
Cisco Ironport Asyncos 6.1.0-306
Cisco Ironport Asyncos 6.1.0-307
Cisco Ironport Asyncos 6.1.5-110
Cisco Ironport Asyncos 6.1.6-003
Cisco Ironport Asyncos 6.3.5-003
Cisco Ironport Asyncos 6.3.6-003
Cisco Ironport Asyncos 6.5.0-405
Cisco Ironport Asyncos 6.5.1-005
Cisco Ironport Asyncos 6.6.4.0-273
Cisco Ironport Email Security Appliances
7.8
CVSSv2
CVE-2015-6291
Cisco AsyncOS prior to 8.5.7-043, 9.x prior to 9.1.1-023, and 9.5.x and 9.6.x prior to 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-matc...
Cisco Email Security Appliance 8.5.6-073
Cisco Email Security Appliance 9.1.0-032
Cisco Email Security Appliance 7.7.0-000
Cisco Email Security Appliance 8.0 Base
Cisco Email Security Appliance 9.0.0-461
Cisco Email Security Appliance 9.0.0-212
Cisco Email Security Appliance 8.5.6-052
Cisco Email Security Appliance 8.5.6-074
Cisco Email Security Appliance 8.5.6-106
Cisco Email Security Appliance 8.5.6-113
Cisco Email Security Appliance 9.6.0-042
Cisco Email Security Appliance 9.0.0
Cisco Email Security Appliance 8.5.7-042
Cisco Email Security Appliance 8.5 Base
Cisco Email Security Appliance 7.7.1-000
Cisco Email Security Appliance 9.0.5-000
10
CVSSv2
CVE-2016-6406
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client prior to 1.0.2-065 is installed, allows remote malicious users to obtain root access via a connect...
Cisco Email Security Appliance Firmware 9.1.2-028
Cisco Email Security Appliance Firmware 9.7.2-047
Cisco Email Security Appliance Firmware 9.1.2-036
Cisco Email Security Appliance Firmware 10.0.0-125
Cisco Email Security Appliance Firmware 10.0.0-124
Cisco Email Security Appliance Firmware 9.7.2-054
Cisco Email Security Appliance Firmware 9.7.2-046
Cisco Email Security Appliance Firmware 9.1.2-023
5
CVSSv2
CVE-2015-4184
The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote malicious users to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733.
Cisco Email Security Appliance 3.331-09
Cisco Email Security Appliance 8.5.6-074
Cisco Email Security Appliance 7.5.1-gpl-022
7.8
CVSSv2
CVE-2017-12215
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote malicious user to cause an affected device to run out of memory and stop scanning and forwarding email messages. When sys...
Cisco Asyncos 9.0
Cisco Asyncos 9.1
Cisco Asyncos 9.1.2
Cisco Asyncos 9.5
Cisco Asyncos 9.6
Cisco Asyncos 9.7
Cisco Asyncos 9.8
4.3
CVSSv2
CVE-2015-4217
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices prior to 2015-06-25 uses the same default SSH host keys across different customers' installations, whi...
Cisco Email Security Virtual Appliance 8.5.7
Cisco Content Security Management Virtual Appliance 9.0.0.087
Cisco Content Security Management Virtual Appliance 8.4.0.0150
Cisco Email Security Virtual Appliance 8.5.6
Cisco Web Security Virtual Appliance 8.7.0
Cisco Web Security Virtual Appliance 7.7.5
Cisco Email Security Virtual Appliance 9.0.0
Cisco Web Security Virtual Appliance 8.5.1
Cisco Web Security Virtual Appliance 8.6.0
Cisco Web Security Virtual Appliance 8.0.5
Cisco Web Security Virtual Appliance 8.5.0
Cisco Email Security Virtual Appliance 8.0.0
7.2
CVSSv2
CVE-2018-0095
A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local malicious user to escalate their privilege level and gain root access. The attacker has to have...
Cisco Asyncos 9.1.1-005
Cisco Asyncos 9.7.2-065
10
CVSSv2
CVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 up to and including 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and previous versions, Heimdal 1.5.1 and previous versions, GNU inetutils, and possibly other products allows remote malicious users...
Mit Krb5-appl
Freebsd Freebsd
Heimdal Project Heimdal
Gnu Inetutils
Fedoraproject Fedora 16
Fedoraproject Fedora 15
Debian Debian Linux 5.0
Debian Debian Linux 7.0
Debian Debian Linux 6.0
Suse Linux Enterprise Desktop 11
Suse Linux Enterprise Server 9
Opensuse Opensuse 11.4
Opensuse Opensuse 11.3
Suse Linux Enterprise Server 10
Suse Linux Enterprise Software Development Kit 10
Suse Linux Enterprise Server 11
Suse Linux Enterprise Desktop 10
Suse Linux Enterprise Software Development Kit 11
3 EDB exploits
5 Github repositories
1 Article
5
CVSSv2
CVE-2015-0207
The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 prior to 1.0.2a does not properly isolate the state information of independent data streams, which allows remote malicious users to cause a denial of service (application crash) via crafted DTLS traffic, as demonstrated by DT...
Openssl Openssl 1.0.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »