2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2899 | — | — | 2.6% | Oct 29, 2015 | Heap-based buffer overflow in the QualifierList retrieve_qualifier_list function in Medicomp MEDCIN Engine before 2.22.2... |
| CVE-2015-2898 | — | — | 3.2% | Oct 29, 2015 | Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to ex... |
| CVE-2015-7649 | — | — | 3.8% | Oct 28, 2015 | Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denial of service (memory... |
| CVE-2015-6034 | — | — | 0.3% | Oct 28, 2015 | EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to ga... |
| CVE-2015-7904 | — | — | 2.8% | Oct 28, 2015 | Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 al... |
| CVE-2015-7903 | — | — | 1.3% | Oct 28, 2015 | SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote... |
| CVE-2015-7902 | — | — | 3.5% | Oct 28, 2015 | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed... |
| CVE-2015-7901 | — | — | 3.3% | Oct 28, 2015 | Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut... |
| CVE-2015-7900 | — | — | 2.9% | Oct 28, 2015 | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive ... |
| CVE-2015-7873 | — | — | 2.6% | Oct 28, 2015 | The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to... |
| CVE-2015-7836 | — | — | 0.9% | Oct 28, 2015 | Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for V... |
| CVE-2015-6494 | — | — | 1.7% | Oct 28, 2015 | Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 ... |
| CVE-2015-6493 | — | — | 1.3% | Oct 28, 2015 | Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 bu... |
| CVE-2015-6491 | — | — | 1.6% | Oct 28, 2015 | Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticate... |
| CVE-2015-6488 | — | — | 2.8% | Oct 28, 2015 | Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 ... |
| CVE-2015-6486 | — | — | 4.3% | Oct 28, 2015 | SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 1... |
| CVE-2015-5713 | — | — | 2.1% | Oct 28, 2015 | Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6... |
| CVE-2015-5712 | — | — | 1.7% | Oct 28, 2015 | Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6... |
| CVE-2015-3973 | — | — | 1.5% | Oct 28, 2015 | Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote att... |
| CVE-2015-3972 | — | — | 2.9% | Oct 28, 2015 | The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, ... |
| CVE-2015-3971 | — | — | 1.6% | Oct 28, 2015 | The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows rem... |
| CVE-2015-3970 | — | — | 1.1% | Oct 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devi... |
| CVE-2015-3969 | — | — | 1.4% | Oct 28, 2015 | Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection informatio... |
| CVE-2015-3968 | — | — | 2.3% | Oct 28, 2015 | The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for rem... |
| CVE-2015-3967 | — | — | 0.6% | Oct 28, 2015 | Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attacke... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now