<?xml version="1.0" encoding="UTF-8"?>
<rss  version="2.0"> 
   <channel>
  <title>Cisco Security Advisories</title>
  <link>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</link>
  <description>Cisco Security Advisories (the 40 most recent advisories)</description>
  <language>en-us</language>
  <copyright>&#xA9; 1992-2013 Cisco Systems, Inc. All rights reserved.</copyright>
  <managingEditor>news-at-cisco-rss@cisco.com</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com</webMaster>
  <pubDate>Wed, 12 Jun 2013 06:40:03 PST</pubDate>
  <lastBuildDate>Wed, 26 Oct 2011 09:00:00 PST</lastBuildDate>
  <category>Security Advisories</category>
  <generator>News@Cisco RSS Script</generator>
  <docs>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</docs>
  <ttl>60</ttl>
  <image>
    <title>News@Cisco</title>
    <url>http://newsroom.cisco.com/images/mobile_newsAtCisco.png</url>
    <link>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</link>
    <width>107</width>
    <height>70</height>
  </image>
  <textInput>
    <title>Search Cisco</title>
    <description></description>
    <name>searchPhrase</name>
    <link>http://www.cisco.com/pcgi-bin/search/search.pl</link>
  </textInput>
  
     <item>
    <title>Attention: New Cisco Security Advisory RSS Feed Locations</title>
    <link>http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml</link>
    <description>Effective October 18, 2011, Cisco has replaced the existing RSS feeds for Cisco Security Advisories. The new RSS feeds for Cisco Security Advisories are available at http://tools.cisco.com/security/center/psirtrss10/CiscoSecurityAdvisory.xml and http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml.  The existing RSS feeds will continue to function until November 19, 2011.  They will not receive updates after this date.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Attention:+New+Cisco+Security+Advisory+RSS+Feed+Locations" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml</guid>
    <pubDate>Wed, 26 Oct 2011 09:00:00 PST</pubDate>
  </item>
  <item>
    <title>Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras</title>
    <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-camera</link>
    <description>A denial of service (DoS) vulnerability exists in the Cisco Video Surveillance IP Cameras 2421, 2500 series and 2600 series of devices. An unauthenticated, remote attacker could exploit this vulnerability by sending crafted RTSP TCP packets to an affected device. Successful exploitation prevents cameras from sending video streams, subsequently causing a reboot. The camera reboot is done automatically and does not require action from an operator.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerability+in+Cisco+Video+Surveillance+IP+Cameras" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-camera</guid>
    <pubDate>Wed, 26 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Contact Center Express Directory Traversal Vulnerability</title>
    <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx</link>
    <description>Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) contain a directory traversal vulnerability that may allow a remote, unauthenticated attacker to retrieve arbitrary files from the filesystem. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Contact+Center+Express+Directory+Traversal+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx</guid>
    <pubDate>Wed, 26 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Manager Directory Traversal Vulnerability</title>
    <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm</link>
    <description>Cisco Unified Communications Manager contains a directory traversal vulnerability that may allow an unauthenticated, remote attacker to retrieve arbitrary files from the filesystem. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Directory+Traversal+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm</guid>
    <pubDate>Wed, 26 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Buffer Overflow Vulnerabilities in the Cisco WebEx Player</title>
    <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex</link>
    <description>Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) player. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system with the privileges of a targeted user.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Buffer+Overflow+Vulnerabilities+in+the+Cisco+WebEx+Player" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex</guid>
    <pubDate>Wed, 26 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Security Agent Remote Code Execution Vulnerabilities</title>
    <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa</link>
    <description>Cisco Security Agent is affected by vulnerabilities that could allow an unauthenticated attacker to perform remote code execution on the affected device. These vulnerabilities are in a third-party library (Oracle Outside In) and are documented in CERT-CC Vulnerability Note VU#520721 at http://www.kb.cert.org/vuls/id/520721&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Security+Agent+Remote+Code+Execution+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa</guid>
    <pubDate>Wed, 26 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Show and Share Security Vulnerabilities</title>
    <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-sns</link>
    <description>The Cisco Show and Share webcasting and video sharing application contains two vulnerabilities. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Show+and+Share+Security+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-sns</guid>
    <pubDate>Wed, 19 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>CiscoWorks Common Services Arbitrary Command Execution Vulnerability</title>
    <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-cs</link>
    <description>CiscoWorks Common Services for Microsoft Windows contains a vulnerability that could allow an authenticated, remote attacker to execute arbitrary commands on the affected system with the privileges of a system administrator.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=CiscoWorks+Common+Services+Arbitrary+Command+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-cs</guid>
    <pubDate>Wed, 19 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco TelePresence Video Communication Server Cross-Site Scripting Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_response09186a0080b98d0b.html</link>
    <description>A vulnerability exists in Cisco TelePresence Video Communication Server (VCS) due to improper validation of user-controlled input to the web-based administrative interface. User-controlled input supplied to the login page via the HTTP User-Agent header is not properly sanitized for illegal or malicious content prior to being returned to the user in dynamically generated web content. A remote attacker could exploit this vulnerability to perform reflected cross-site scripting attacks.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+TelePresence+Video+Communication+Server+Cross-Site+Scripting+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_response09186a0080b98d0b.html</guid>
    <pubDate>Wed, 12 Oct 2011 10:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software Smart Install Remote Code Execution Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4f.shtml</link>
    <description>A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Smart+Install+Remote+Code+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4f.shtml</guid>
    <pubDate>Tue, 11 Oct 2011 11:15:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software IP Service Level Agreement Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4c.shtml</link>
    <description>The Cisco IOS IP Service Level Agreement (IP SLA) feature contains a denial of service (DoS) vulnerability. The vulnerability is triggered when malformed UDP packets are sent to a vulnerable device. The vulnerable UDP port numbers depend on the device configuration. Default ports are not used for the vulnerable UDP IP SLA operation or for the UDP responder ports.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IP+Service+Level+Agreement+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4c.shtml</guid>
    <pubDate>Mon, 10 Oct 2011 12:20:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97900.shtml</link>
    <description>Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module are affected by multiple vulnerabilities as follows:&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+ASA+5500+Series+Adaptive+Security+Appliances+and+Cisco+Catalyst+6500+Series+ASA+Services+Module" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97900.shtml</guid>
    <pubDate>Wed, 05 Oct 2011 13:45:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Cisco Firewall Services Module</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97904.shtml </link>
    <description>The Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 Series switches and Cisco 7600 Series routers is affected by the following vulnerabilities:&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+Firewall+Services+Module" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97904.shtml </guid>
    <pubDate>Wed, 05 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Directory Traversal Vulnerability in Cisco Network Admission Control Manager</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97901.shtml </link>
    <description>Cisco Network Admission Control (NAC) Manager contains a directory traversal vulnerability that may allow an unauthenticated attacker to obtain system information.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Directory+Traversal+Vulnerability+in+Cisco+Network+Admission+Control+Manager" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97901.shtml </guid>
    <pubDate>Wed, 05 Oct 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Identity Services Engine Database Default Credentials Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95105.shtml</link>
    <description>Cisco Identity Services Engine (ISE) contains a set of default credentials for its underlying database. A remote attacker could use those credentials to modify the device configuration and settings or gain complete administrative control of the device. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Identity+Services+Engine+Database+Default+Credentials+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95105.shtml</guid>
    <pubDate>Mon, 03 Oct 2011 08:45:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco 10000 Series Denial of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d50.shtml</link>
    <description>The Cisco 10000 Series Router is affected by a denial of service (DoS) vulnerability that can allow an attacker to cause a device reload by sending a series of ICMP packets.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+10000+Series+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d50.shtml</guid>
    <pubDate>Fri, 30 Sep 2011 15:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software IPv6 over MPLS Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d52.shtml</link>
    <description>Cisco IOS Software is affected by two vulnerabilities that cause a Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a Multiprotocol Label Switching (MPLS) domain.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IPv6+over+MPLS+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d52.shtml</guid>
    <pubDate>Fri, 30 Sep 2011 15:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software IPv6 Denial of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d59.shtml</link>
    <description>Cisco IOS Software contains a vulnerability in the IP version 6 (IPv6) protocol stack implementation that could allow an unauthenticated, remote attacker to cause a reload of an affected device that has IPv6 enabled. The vulnerability may be triggered when the device processes a malformed IPv6 packet.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IPv6+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d59.shtml</guid>
    <pubDate>Fri, 30 Sep 2011 15:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d5a.shtml</link>
    <description>Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software and Cisco IOS XE Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or trigger memory leaks that may result in system instabilities. Affected devices would need to be configured to process SIP messages for these vulnerabilities to be exploitable.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Session+Initiation+Protocol+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d5a.shtml</guid>
    <pubDate>Fri, 30 Sep 2011 15:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software IPS and Zone-Based Firewall Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d57.shtml</link>
    <description>Cisco IOS Software contains two vulnerabilities related to Cisco IOS Intrusion Prevention System (IPS) and Cisco IOS Zone-Based Firewall features.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IPS+and+Zone-Based+Firewall+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d57.shtml</guid>
    <pubDate>Fri, 30 Sep 2011 15:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software Data-Link Switching Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4e.shtml</link>
    <description>Cisco IOS Software contains a memory leak vulnerability in the Data-Link Switching (DLSw) feature that could result in a device reload when processing crafted IP Protocol 91 packets.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Data-Link+Switching+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4e.shtml</guid>
    <pubDate>Fri, 30 Sep 2011 15:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Software Network Address Translation Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4d.shtml</link>
    <description>The Cisco IOS Software network address translation (NAT) feature contains multiple denial of service (DoS) vulnerabilities in the translation of the following protocols: NetMeeting Directory (Lightweight Directory Access Protocol, LDAP); Session Initiation Protocol (Multiple vulnerabilities); H.323 protocol&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Network+Address+Translation+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4d.shtml</guid>
    <pubDate>Fri, 30 Sep 2011 10:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Manager Session Initiation Protocol Memory Leak Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d58.shtml</link>
    <description>Cisco Unified Communications Manager contains a memory leak vulnerability that could be triggered through the processing of malformed Session Initiation Protocol (SIP) messages. Exploitation of this vulnerability could cause an interruption of voice services. Cisco has released free software updates for supported Cisco Unified Communications Manager versions to address the vulnerability. A workaround exists for this SIP vulnerability. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Session+Initiation+Protocol+Memory+Leak+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d58.shtml</guid>
    <pubDate>Wed, 28 Sep 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Jabber Extensible Communications Platform and Cisco Unified Presence XML Denial of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d47.shtml</link>
    <description>A denial of service (DoS) vulnerability exists in Jabber Extensible Communications Platform (Jabber XCP) and Cisco Unified Presence. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious XML to an affected server. Successful exploitation of this vulnerability could cause elevated memory and CPU utilization, resulting in memory exhaustion and process crashes. Repeated exploitation could result in a sustained DoS condition.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Jabber+Extensible+Communications+Platform+and+Cisco+Unified+Presence+XML+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d47.shtml</guid>
    <pubDate>Wed, 28 Sep 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>CiscoWorks LAN Management Solution Remote Code Execution Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtml</link>
    <description>Two vulnerabilities exist in CiscoWorks LAN Management Solution software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=CiscoWorks+LAN+Management+Solution+Remote+Code+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtml</guid>
    <pubDate>Wed, 14 Sep 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Service Monitor and Cisco Unified Operations Manager Remote Code Execution Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtml</link>
    <description>Two vulnerabilities exist in Cisco Unified Service Monitor and Cisco Unified Operations Manager software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Service+Monitor+and+Cisco+Unified+Operations+Manager+Remote+Code+Execution+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtml</guid>
    <pubDate>Wed, 14 Sep 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Apache HTTPd Range Header Denial of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml</link>
    <description>The Apache HTTPd server contains a denial of service vulnerability when it handles multiple, overlapping ranges. Multiple Cisco products may be affected by this vulnerability. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Apache+HTTPd+Range+Header+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml</guid>
    <pubDate>Thu, 08 Sep 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9250c.shtml</link>
    <description>A vulnerability exists in Cisco Nexus 5000 and 3000 Series Switches that may allow traffic to bypass deny statements in access control lists (ACLs) that are configured on the device. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Nexus+5000+and+3000+Series+Switches+Access+Control+List+Bypass+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9250c.shtml</guid>
    <pubDate>Wed, 07 Sep 2011 07:30:00 PST</pubDate>
  </item>
  <item>
    <title>Denial of Service Vulnerability in Cisco TelePresence Codecs</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b91395.shtml</link>
    <description>Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs that are running software versions prior to TC4.0.0 or F9.1 contain a vulnerability that could allow an attacker to cause a denial of service.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerability+in+Cisco+TelePresence+Codecs" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b91395.shtml</guid>
    <pubDate>Thu, 01 Sep 2011 13:00:00 PST</pubDate>
  </item>
  <item>
    <title>Open Query Interface in Cisco Unified Communications Manager and Cisco Unified Presence Server</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f532.shtml</link>
    <description>Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Open+Query+Interface+in+Cisco+Unified+Communications+Manager+and+Cisco+Unified+Presence+Server" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f532.shtml</guid>
    <pubDate>Fri, 26 Aug 2011 14:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Manager Denial of Service Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f531.shtml</link>
    <description>Cisco Unified Communications Manager contains five (5) denial of service (DoS) vulnerabilities.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f531.shtml</guid>
    <pubDate>Wed, 24 Aug 2011 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Denial of Service Vulnerabilities in Cisco Intercompany Media Engine</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f533.shtml</link>
    <description>Two denial of service (DoS) vulnerabilities exist in the Cisco Intercompany Media Engine. An unauthenticated attacker could exploit these vulnerabilities by sending crafted Service Advertisement Framework (SAF) packets to an affected device, which may cause the device to reload.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerabilities+in+Cisco+Intercompany+Media+Engine" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f533.shtml</guid>
    <pubDate>Wed, 24 Aug 2011 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8ad3f.shtml</link>
    <description>Cisco TelePresence Recording Server Software Release 1.7.2.0 includes a root administrator account that is enabled by default. Successful exploitation of the vulnerability could allow a remote attacker to use these default credentials to modify the system configuration and settings. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+TelePresence+Recording+Server+Default+Credentials+for+Root+Account+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8ad3f.shtml</guid>
    <pubDate>Fri, 29 Jul 2011 06:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco SA 500 Series Security Appliances Web Management Interface Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8915e.shtml</link>
    <description>Cisco SA 500 Series Security Appliances are affected by two vulnerabilities on their web-based management interface. An attacker must have valid credentials for an affected device to exploit one vulnerability; exploitation of the other does not require authentication. Both vulnerabilities can be exploited over the network. Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+SA+500+Series+Security+Appliances+Web+Management+Interface+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8915e.shtml</guid>
    <pubDate>Wed, 20 Jul 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco ASR 9000 Series Routers Line Card IP Version 4 Denial of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b89155.shtml</link>
    <description>Cisco 9000 Series Aggregation Services Routers (ASR) running Cisco IOS XR Software version 4.1.0 contain a vulnerability that may cause a network processor in a line card to lock up while processing an IP version 4 (IPv4) packet. As a consequence of the network processor lockup, the line card that is processing the offending packet will automatically reload. Cisco has released a free software maintenance upgrade (SMU) to address this vulnerability. There are no workarounds for this vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+ASR+9000+Series+Routers+Line+Card+IP+Version+4+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b89155.shtml</guid>
    <pubDate>Wed, 20 Jul 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80123.shtml</link>
    <description>The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by multiple vulnerabilities. Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Cisco has released free software updates that address these vulnerabilities. There are no workarounds for the vulnerabilities described in this advisory.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+AnyConnect+Secure+Mobility+Client" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80123.shtml</guid>
    <pubDate>Mon, 11 Jul 2011 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Content Services Gateway Denial of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b86503.shtml</link>
    <description>A denial of service (DoS) vulnerability exists in the Cisco Content Services Gateway - Second Generation, that runs on the Cisco Service and Application Module for IP (SAMI). An unauthenticated, remote attacker could exploit this vulnerability by sending a series of crafted ICMP packets to an affected device. Exploitation could cause the device to reload. There are no workarounds available to mitigate exploitation of this vulnerability other than blocking ICMP traffic destined to the affected device.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Content+Services+Gateway+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b86503.shtml</guid>
    <pubDate>Wed, 06 Jul 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco RVS4000 and WRVS4400N Web Management Interface Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b7f190.shtml</link>
    <description>Cisco RVS4000 4-port Gigabit Security Routers and Cisco WRVS4400N Wireless-N Gigabit Security Routers have several web interface vulnerabilities that can be exploited by a remote, unauthenticated user.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+RVS4000+and+WRVS4400N+Web+Management+Interface+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b7f190.shtml</guid>
    <pubDate>Fri, 17 Jun 2011 07:30:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80111.shtml</link>
    <description>Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+Unified+IP+Phones+7900+Series" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80111.shtml</guid>
    <pubDate>Wed, 01 Jun 2011 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Default Credentials Vulnerability in Cisco Network Registrar</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80121.shtml</link>
    <description>Cisco Network Registrar Software Releases prior to 7.2 contain a default password for the administrative account. During the initial installation, users are not forced to change this password, allowing it to persist after the installation. An attacker who is aware of this vulnerability could authenticate with administrative privileges and arbitrarily change the configuration of Cisco Network Registrar.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Default+Credentials+Vulnerability+in+Cisco+Network+Registrar" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80121.shtml</guid>
    <pubDate>Wed, 01 Jun 2011 08:00:00 PST</pubDate>
  </item>
</channel>
   </rss>