2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8397 | HIGH | 8.2 | 3.6% | Jan 12, 2016 | The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) b... |
| CVE-2015-8396 | — | — | 16.8% | Jan 12, 2016 | Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx... |
| CVE-2015-7759 | — | — | 1.5% | Jan 12, 2016 | BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtua... |
| CVE-2015-7393 | — | — | 0.3% | Jan 12, 2016 | dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP... |
| CVE-2015-8659 | — | — | 4.1% | Jan 12, 2016 | The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a ... |
| CVE-2015-8603 | — | — | 1.2% | Jan 12, 2016 | Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web scr... |
| CVE-2015-8400 | — | — | 2.0% | Jan 12, 2016 | The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers t... |
| CVE-2015-8337 | — | — | 0.8% | Jan 12, 2016 | The HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B220SP01, GRA-CL00 before GRA-CL00C92B220, ... |
| CVE-2015-8306 | — | — | 1.1% | Jan 12, 2016 | Buffer overflow in the HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GR... |
| CVE-2015-8098 | — | — | 4.7% | Jan 12, 2016 | F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cau... |
| CVE-2015-8088 | — | — | 3.8% | Jan 12, 2016 | Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7... |
| CVE-2015-7548 | — | — | 1.8% | Jan 12, 2016 | OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instance... |
| CVE-2015-7242 | — | — | 1.5% | Jan 12, 2016 | Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote att... |
| CVE-2015-5471 | — | — | 32.7% | Jan 12, 2016 | Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo... |
| CVE-2015-4703 | — | — | 2.9% | Jan 12, 2016 | Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows ... |
| CVE-2015-4671 | — | — | 1.5% | Jan 12, 2016 | Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web scri... |
| CVE-2015-1779 | HIGH | 8.6 | 7.4% | Jan 12, 2016 | The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption... |
| CVE-2015-8335 | — | — | 0.7% | Jan 11, 2016 | Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated user... |
| CVE-2015-8333 | — | — | 0.8% | Jan 11, 2016 | The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authentic... |
| CVE-2015-8331 | — | — | 0.8% | Jan 11, 2016 | The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly inval... |
| CVE-2015-8231 | — | — | 1.0% | Jan 11, 2016 | Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established ses... |
| CVE-2015-8230 | — | — | 1.0% | Jan 11, 2016 | Memory leak in Huawei eSpace 8950 IP phones with software before V200R003C00SPC300 allows remote attackers to cause a de... |
| CVE-2015-7706 | — | — | 1.5% | Jan 11, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to ... |
| CVE-2015-6566 | — | — | 0.4% | Jan 11, 2016 | zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symli... |
| CVE-2015-7399 | — | — | 1.9% | Jan 11, 2016 | IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 befor... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now