2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-5318Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which ma...
CVE-2015-5317HIGH7.5The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive j...
CVE-2015-5306OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote at...
CVE-2015-5242OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metada...
CVE-2015-8342Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-8135Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7265. Reason: This candidate is a reservation du...
CVE-2015-8134Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-8133Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7264. Reason: This candidate is a reservation du...
CVE-2015-8132Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7263. Reason: This candidate is a reservation du...
CVE-2015-7288CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 allow remote attackers to modify the configuration via...
CVE-2015-7287CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different custo...
CVE-2015-7286CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hard...
CVE-2015-7285CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Cen...
CVE-2015-6379The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authent...
CVE-2015-8330The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption an...
CVE-2015-8329SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which all...
CVE-2015-8328Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 3...
CVE-2015-8229Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow re...
CVE-2015-8228Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 ro...
CVE-2015-8227The built-in web server in Huawei VP9660 multi-point control unit with software before V200R001C30SPC700 allows remote a...
CVE-2015-7985Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to...
CVE-2015-7981The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17...
CVE-2015-7869Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before ...
CVE-2015-7866Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the ...
CVE-2015-7865nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now