2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8458 | — | — | 8.3% | Dec 21, 2015 | Heap-based buffer overflow in AGM.dll in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat a... |
| CVE-2015-7937 | — | — | 7.4% | Dec 21, 2015 | Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices al... |
| CVE-2015-7919 | — | — | 22.0% | Dec 21, 2015 | SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of serv... |
| CVE-2015-7908 | — | — | 2.0% | Dec 21, 2015 | Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discov... |
| CVE-2015-7907 | — | — | 3.6% | Dec 21, 2015 | Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas d... |
| CVE-2015-7906 | — | — | 2.3% | Dec 21, 2015 | LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backu... |
| CVE-2015-7413 | — | — | 1.2% | Dec 21, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows... |
| CVE-2015-6481 | — | — | 1.7% | Dec 21, 2015 | The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root passwor... |
| CVE-2015-6480 | — | — | 1.8% | Dec 21, 2015 | The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows... |
| CVE-2015-5001 | — | — | 2.1% | Dec 21, 2015 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.... |
| CVE-2015-4998 | — | — | 1.4% | Dec 21, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,... |
| CVE-2015-4993 | — | — | 1.4% | Dec 21, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,... |
| CVE-2015-1836 | — | — | 7.4% | Dec 21, 2015 | Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.... |
| CVE-2015-1772 | — | — | 6.8% | Dec 21, 2015 | The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere Big... |
| CVE-2015-6934 | — | — | 5.0% | Dec 21, 2015 | Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCe... |
| CVE-2015-7756 | — | — | 2.4% | Dec 19, 2015 | The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before ... |
| CVE-2015-6429 | — | — | 1.7% | Dec 19, 2015 | The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a d... |
| CVE-2015-6556 | — | — | 0.3% | Dec 18, 2015 | EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows ... |
| CVE-2015-6428 | — | — | 2.4% | Dec 18, 2015 | Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP reques... |
| CVE-2015-6427 | — | — | 1.7% | Dec 18, 2015 | Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggeri... |
| CVE-2015-6426 | — | — | 0.4% | Dec 18, 2015 | Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitr... |
| CVE-2015-6424 | — | — | 0.4% | Dec 18, 2015 | The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass i... |
| CVE-2015-8602 | — | — | 0.9% | Dec 17, 2015 | The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remot... |
| CVE-2015-8601 | — | — | 1.2% | Dec 17, 2015 | The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket f... |
| CVE-2015-8600 | — | — | 1.4% | Dec 17, 2015 | The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now