2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8664 | — | — | 5.5% | Dec 24, 2015 | Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 4... |
| CVE-2015-6792 | — | — | 4.0% | Dec 24, 2015 | The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remo... |
| CVE-2015-8663 | — | — | 1.9% | Dec 24, 2015 | The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failur... |
| CVE-2015-8662 | — | — | 1.9% | Dec 24, 2015 | The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposit... |
| CVE-2015-8661 | — | — | 1.9% | Dec 24, 2015 | The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship... |
| CVE-2015-7934 | — | — | 2.2% | Dec 24, 2015 | The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file path... |
| CVE-2015-7932 | — | — | 1.5% | Dec 24, 2015 | Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing ... |
| CVE-2015-7931 | — | — | 1.3% | Dec 24, 2015 | The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which a... |
| CVE-2015-7930 | — | — | 2.5% | Dec 24, 2015 | Adcon Telemetry A840 Telemetry Gateway Base Station has hardcoded credentials, which allows remote attackers to obtain a... |
| CVE-2015-8267 | — | — | 2.4% | Dec 24, 2015 | The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Pass... |
| CVE-2015-7929 | — | — | 2.6% | Dec 23, 2015 | eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain... |
| CVE-2015-7928 | — | — | 3.2% | Dec 23, 2015 | eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it ... |
| CVE-2015-7927 | — | — | 2.0% | Dec 23, 2015 | Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject ... |
| CVE-2015-7926 | — | — | 3.4% | Dec 23, 2015 | eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote a... |
| CVE-2015-7925 | — | — | 1.2% | Dec 23, 2015 | Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to ... |
| CVE-2015-7924 | — | — | 2.1% | Dec 23, 2015 | eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off ... |
| CVE-2015-7936 | — | — | 0.6% | Dec 23, 2015 | Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijac... |
| CVE-2015-7935 | — | — | 1.5% | Dec 23, 2015 | Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors. |
| CVE-2015-7917 | — | — | 0.4% | Dec 23, 2015 | Untrusted search path vulnerability in Open Automation OPC Systems.NET 8.00.0023 and earlier allows local users to gain ... |
| CVE-2015-7911 | — | — | 2.4% | Dec 23, 2015 | Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7... |
| CVE-2015-6851 | — | — | 0.6% | Dec 23, 2015 | EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mecha... |
| CVE-2015-6471 | — | — | 1.1% | Dec 23, 2015 | Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not prope... |
| CVE-2015-6431 | — | — | 0.7% | Dec 23, 2015 | Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-... |
| CVE-2015-8373 | — | — | 3.7% | Dec 22, 2015 | The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow rem... |
| CVE-2015-4545 | — | — | 2.2% | Dec 21, 2015 | EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now