Cisco / Web Security Virtual Appliance
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-1271 | Cisco Web Security Appliance Stored Cross-Site Scripting Vulnerability | MEDIUM | 4.8 | Jan 20, 2021 |
| CVE-2017-6751 | A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward traffic fro… | HIGH | 7.5 | Jul 25, 2017 |
| CVE-2017-6750 | A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privilege… | HIGH | 7.5 | Jul 25, 2017 |
| CVE-2017-6749 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored c… | MEDIUM | 5.4 | Jul 25, 2017 |
| CVE-2017-6748 | A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and eleva… | MEDIUM | 6.7 | Jul 25, 2017 |
| CVE-2015-6290 | Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted re… | MEDIUM | 4.3 | Sep 14, 2015 |
| CVE-2015-6287 | Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic tha… | MEDIUM | 5.0 | Sep 14, 2015 |
| CVE-2015-4217 | The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (… | MEDIUM | 4.3 | Jun 26, 2015 |
| CVE-2015-4216 | The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (… | MEDIUM | 5.0 | Jun 26, 2015 |
| CVE-2014-2137 | CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and earlier allows remote attackers to inject arbitrary HTTP header… | MEDIUM | 4.3 | Apr 2, 2014 |
Showing 1 to 10 of 10 CVEs