2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6369 | — | — | 0.3% | Nov 19, 2015 | The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically pro... |
| CVE-2015-6368 | — | — | 1.2% | Nov 19, 2015 | Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files v... |
| CVE-2015-8090 | — | — | 1.1% | Nov 18, 2015 | The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and ... |
| CVE-2015-8053 | — | — | 3.1% | Nov 18, 2015 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote at... |
| CVE-2015-8052 | — | — | 3.1% | Nov 18, 2015 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote at... |
| CVE-2015-8051 | — | — | 4.2% | Nov 18, 2015 | The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vecto... |
| CVE-2015-5255 | — | — | 4.5% | Nov 18, 2015 | Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before... |
| CVE-2015-8035 | — | — | 3.2% | Nov 18, 2015 | The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dep... |
| CVE-2015-8023 | — | — | 2.6% | Nov 18, 2015 | The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x befor... |
| CVE-2015-7942 | — | — | 4.7% | Nov 18, 2015 | The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it sto... |
| CVE-2015-7941 | — | — | 3.1% | Nov 18, 2015 | libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial o... |
| CVE-2015-5999 | — | — | 3.2% | Nov 18, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2... |
| CVE-2015-5253 | — | — | 5.7% | Nov 18, 2015 | The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authentica... |
| CVE-2015-6373 | — | — | 0.6% | Nov 18, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9... |
| CVE-2015-6372 | — | — | 1.0% | Nov 18, 2015 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating S... |
| CVE-2015-6847 | — | — | 0.5% | Nov 18, 2015 | The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log... |
| CVE-2015-6357 | — | — | 2.6% | Nov 18, 2015 | The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certific... |
| CVE-2015-6330 | — | — | 0.6% | Nov 18, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote at... |
| CVE-2015-8233 | — | — | 1.3% | Nov 17, 2015 | Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal ... |
| CVE-2015-8232 | — | — | 1.1% | Nov 17, 2015 | The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstan... |
| CVE-2015-8222 | — | — | 0.4% | Nov 17, 2015 | The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions f... |
| CVE-2015-8221 | — | — | 4.0% | Nov 17, 2015 | Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAM... |
| CVE-2015-8220 | — | — | 4.8% | Nov 17, 2015 | Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFi... |
| CVE-2015-7998 | — | — | 1.0% | Nov 17, 2015 | The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build ... |
| CVE-2015-7997 | — | — | 1.0% | Nov 17, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now