2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6029 | — | — | 4.4% | Nov 4, 2015 | HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier fo... |
| CVE-2015-5673 | — | — | 2.5% | Nov 4, 2015 | eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper p... |
| CVE-2015-5021 | — | — | 2.3% | Nov 4, 2015 | IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execu... |
| CVE-2015-4927 | — | — | 0.4% | Nov 4, 2015 | The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 befor... |
| CVE-2015-2903 | — | — | 1.3% | Nov 4, 2015 | The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for ... |
| CVE-2015-2902 | — | — | 1.5% | Nov 4, 2015 | HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-m... |
| CVE-2015-8074 | — | — | 0.9% | Nov 3, 2015 | mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently byp... |
| CVE-2015-8073 | — | — | 2.2% | Nov 3, 2015 | mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a deni... |
| CVE-2015-8072 | — | — | 2.2% | Nov 3, 2015 | mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute ... |
| CVE-2015-6614 | — | — | 0.6% | Nov 3, 2015 | Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended netwo... |
| CVE-2015-6613 | — | — | 0.6% | Nov 3, 2015 | Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port... |
| CVE-2015-6612 | — | — | 2.6% | Nov 3, 2015 | libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted appl... |
| CVE-2015-6611 | — | — | 1.0% | Nov 3, 2015 | mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive informa... |
| CVE-2015-6610 | — | — | 0.8% | Nov 3, 2015 | libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges or cause a d... |
| CVE-2015-6609 | — | — | 2.2% | Nov 3, 2015 | libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or c... |
| CVE-2015-6608 | — | — | 2.4% | Nov 3, 2015 | mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary co... |
| CVE-2015-8040 | — | — | 3.4% | Nov 2, 2015 | The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrar... |
| CVE-2015-8039 | — | — | 3.9% | Nov 2, 2015 | Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave me... |
| CVE-2015-8038 | — | — | 2.8% | Nov 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor... |
| CVE-2015-8037 | — | — | 2.8% | Nov 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor... |
| CVE-2015-8036 | — | — | 2.9% | Nov 2, 2015 | Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SS... |
| CVE-2015-6031 | — | — | 4.8% | Nov 2, 2015 | Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.201509... |
| CVE-2015-5534 | — | — | 2.3% | Nov 2, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the aut... |
| CVE-2015-5470 | — | — | 11.3% | Nov 2, 2015 | The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) ... |
| CVE-2015-5308 | — | — | 2.2% | Nov 2, 2015 | Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remot... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now