Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.