2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7285 | — | — | 1.5% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Cen... |
| CVE-2015-6379 | — | — | 1.5% | Nov 25, 2015 | The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authent... |
| CVE-2015-8330 | — | — | 3.0% | Nov 24, 2015 | The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption an... |
| CVE-2015-8329 | — | — | 1.0% | Nov 24, 2015 | SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which all... |
| CVE-2015-8328 | — | — | 0.4% | Nov 24, 2015 | Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 3... |
| CVE-2015-8229 | — | — | 0.7% | Nov 24, 2015 | Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow re... |
| CVE-2015-8228 | — | — | 1.1% | Nov 24, 2015 | Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 ro... |
| CVE-2015-8227 | — | — | 0.7% | Nov 24, 2015 | The built-in web server in Huawei VP9660 multi-point control unit with software before V200R001C30SPC700 allows remote a... |
| CVE-2015-7985 | — | — | 0.9% | Nov 24, 2015 | Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to... |
| CVE-2015-7981 | — | — | 6.5% | Nov 24, 2015 | The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17... |
| CVE-2015-7869 | — | — | 0.4% | Nov 24, 2015 | Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before ... |
| CVE-2015-7866 | — | — | 0.5% | Nov 24, 2015 | Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the ... |
| CVE-2015-7865 | — | — | 2.6% | Nov 24, 2015 | nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before ... |
| CVE-2015-7808 | — | — | 80.6% | Nov 24, 2015 | The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH... |
| CVE-2015-7496 | — | — | 0.4% | Nov 24, 2015 | GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the... |
| CVE-2015-5281 | — | — | 0.3% | Nov 24, 2015 | The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users t... |
| CVE-2015-5053 | — | — | 1.7% | Nov 24, 2015 | The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Lin... |
| CVE-2015-0856 | — | — | 0.4% | Nov 24, 2015 | daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to ga... |
| CVE-2015-6380 | — | — | 1.1% | Nov 24, 2015 | An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 d... |
| CVE-2015-6377 | — | — | 1.9% | Nov 24, 2015 | Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memo... |
| CVE-2015-8320 | — | — | 4.4% | Nov 23, 2015 | Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for ... |
| CVE-2015-5275 | — | — | — | Nov 23, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-5257. Reason: This candidate is a reservation du... |
| CVE-2015-5256 | — | — | 4.2% | Nov 23, 2015 | Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript w... |
| CVE-2015-5451 | — | — | 1.5% | Nov 23, 2015 | Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remo... |
| CVE-2015-7036 | — | — | 39.3% | Nov 22, 2015 | The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now