2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8087 | — | — | 0.9% | Nov 19, 2015 | Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with so... |
| CVE-2015-8083 | — | — | 1.0% | Nov 19, 2015 | An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software befor... |
| CVE-2015-7984 | — | — | 4.1% | Nov 19, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Hor... |
| CVE-2015-7845 | — | — | 0.9% | Nov 19, 2015 | The exception handling mechanism in the CLI Module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified... |
| CVE-2015-7385 | — | — | 2.0% | Nov 19, 2015 | Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject a... |
| CVE-2015-0794 | — | — | 0.3% | Nov 19, 2015 | modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have u... |
| CVE-2015-8236 | — | — | 4.2% | Nov 19, 2015 | Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.... |
| CVE-2015-7910 | — | — | 2.1% | Nov 19, 2015 | Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows re... |
| CVE-2015-4112 | — | — | 1.1% | Nov 19, 2015 | The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elem... |
| CVE-2015-6374 | — | — | 0.8% | Nov 19, 2015 | The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly ... |
| CVE-2015-6371 | — | — | 1.0% | Nov 19, 2015 | Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to re... |
| CVE-2015-6370 | — | — | 0.4% | Nov 19, 2015 | The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices a... |
| CVE-2015-6369 | — | — | 0.3% | Nov 19, 2015 | The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically pro... |
| CVE-2015-6368 | — | — | 1.2% | Nov 19, 2015 | Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files v... |
| CVE-2015-8090 | — | — | 1.1% | Nov 18, 2015 | The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and ... |
| CVE-2015-8053 | — | — | 3.1% | Nov 18, 2015 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote at... |
| CVE-2015-8052 | — | — | 3.1% | Nov 18, 2015 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote at... |
| CVE-2015-8051 | — | — | 4.2% | Nov 18, 2015 | The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vecto... |
| CVE-2015-5255 | — | — | 4.5% | Nov 18, 2015 | Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before... |
| CVE-2015-8035 | — | — | 3.2% | Nov 18, 2015 | The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dep... |
| CVE-2015-8023 | — | — | 2.6% | Nov 18, 2015 | The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x befor... |
| CVE-2015-7942 | — | — | 4.7% | Nov 18, 2015 | The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it sto... |
| CVE-2015-7941 | — | — | 3.1% | Nov 18, 2015 | libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial o... |
| CVE-2015-5999 | — | — | 3.2% | Nov 18, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2... |
| CVE-2015-5253 | — | — | 5.7% | Nov 18, 2015 | The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authentica... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now