2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5318 | — | — | 1.1% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which ma... |
| CVE-2015-5317 | HIGH | 7.5 | 22.4% | Nov 25, 2015 | The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive j... |
| CVE-2015-5306 | — | — | 1.6% | Nov 25, 2015 | OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote at... |
| CVE-2015-5242 | — | — | 2.2% | Nov 25, 2015 | OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metada... |
| CVE-2015-8342 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2015-8135 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7265. Reason: This candidate is a reservation du... |
| CVE-2015-8134 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2015-8133 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7264. Reason: This candidate is a reservation du... |
| CVE-2015-8132 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7263. Reason: This candidate is a reservation du... |
| CVE-2015-7288 | — | — | 1.7% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 allow remote attackers to modify the configuration via... |
| CVE-2015-7287 | — | — | 3.2% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different custo... |
| CVE-2015-7286 | — | — | 2.1% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hard... |
| CVE-2015-7285 | — | — | 1.5% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Cen... |
| CVE-2015-6379 | — | — | 1.5% | Nov 25, 2015 | The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authent... |
| CVE-2015-8330 | — | — | 3.0% | Nov 24, 2015 | The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption an... |
| CVE-2015-8329 | — | — | 1.0% | Nov 24, 2015 | SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which all... |
| CVE-2015-8328 | — | — | 0.4% | Nov 24, 2015 | Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 3... |
| CVE-2015-8229 | — | — | 0.7% | Nov 24, 2015 | Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow re... |
| CVE-2015-8228 | — | — | 1.1% | Nov 24, 2015 | Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 ro... |
| CVE-2015-8227 | — | — | 0.7% | Nov 24, 2015 | The built-in web server in Huawei VP9660 multi-point control unit with software before V200R001C30SPC700 allows remote a... |
| CVE-2015-7985 | — | — | 0.9% | Nov 24, 2015 | Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to... |
| CVE-2015-7981 | — | — | 6.5% | Nov 24, 2015 | The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17... |
| CVE-2015-7869 | — | — | 0.4% | Nov 24, 2015 | Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before ... |
| CVE-2015-7866 | — | — | 0.5% | Nov 24, 2015 | Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the ... |
| CVE-2015-7865 | — | — | 2.6% | Nov 24, 2015 | nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now