2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4940 | — | — | 0.7% | Nov 8, 2015 | Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in... |
| CVE-2015-4928 | — | — | 2.8% | Nov 8, 2015 | Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Config... |
| CVE-2015-2017 | — | — | 1.9% | Nov 8, 2015 | CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 be... |
| CVE-2015-1999 | — | — | 1.2% | Nov 8, 2015 | IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote ... |
| CVE-2015-1997 | — | — | 0.6% | Nov 8, 2015 | Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar Vulnerability Manager 7.2.x before 7.2.5 Patch 5 ... |
| CVE-2015-1996 | — | — | 0.3% | Nov 8, 2015 | IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which all... |
| CVE-2015-1995 | — | — | 1.0% | Nov 8, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5... |
| CVE-2015-1994 | — | — | 1.2% | Nov 8, 2015 | IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie hea... |
| CVE-2015-1993 | — | — | 1.2% | Nov 8, 2015 | IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies i... |
| CVE-2015-1989 | — | — | 1.0% | Nov 8, 2015 | SQL injection vulnerability in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allows remote authentic... |
| CVE-2015-7395 | — | — | 1.0% | Nov 8, 2015 | IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo A... |
| CVE-2015-7254 | — | — | 27.5% | Nov 7, 2015 | Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary... |
| CVE-2015-6476 | — | — | 2.3% | Nov 7, 2015 | Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x device... |
| CVE-2015-8082 | — | — | 1.6% | Nov 6, 2015 | The Login Disable module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly load the user_lo... |
| CVE-2015-8081 | — | — | 1.2% | Nov 6, 2015 | The Field as Block module 7.x-1.x before 7.x-1.4 for Drupal might allow remote attackers to obtain sensitive field infor... |
| CVE-2015-7809 | — | — | 3.4% | Nov 6, 2015 | The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote at... |
| CVE-2015-7763 | — | — | 2.1% | Nov 6, 2015 | rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padd... |
| CVE-2015-7762 | — | — | 2.1% | Nov 6, 2015 | rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure wh... |
| CVE-2015-6855 | HIGH | 7.5 | 3.5% | Nov 6, 2015 | hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to c... |
| CVE-2015-5225 | — | — | 0.5% | Nov 6, 2015 | Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest... |
| CVE-2015-7697 | — | — | 6.1% | Nov 6, 2015 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP ar... |
| CVE-2015-7696 | — | — | 7.2% | Nov 6, 2015 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application cra... |
| CVE-2015-7394 | — | — | 3.9% | Nov 6, 2015 | The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 1... |
| CVE-2015-6546 | — | — | 0.7% | Nov 6, 2015 | The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 be... |
| CVE-2015-5305 | — | — | 1.8% | Nov 6, 2015 | Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now