2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6613 | — | — | 0.6% | Nov 3, 2015 | Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port... |
| CVE-2015-6612 | — | — | 2.6% | Nov 3, 2015 | libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted appl... |
| CVE-2015-6611 | — | — | 1.0% | Nov 3, 2015 | mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive informa... |
| CVE-2015-6610 | — | — | 0.8% | Nov 3, 2015 | libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges or cause a d... |
| CVE-2015-6609 | — | — | 2.2% | Nov 3, 2015 | libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or c... |
| CVE-2015-6608 | — | — | 2.4% | Nov 3, 2015 | mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary co... |
| CVE-2015-8040 | — | — | 3.4% | Nov 2, 2015 | The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrar... |
| CVE-2015-8039 | — | — | 3.9% | Nov 2, 2015 | Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave me... |
| CVE-2015-8038 | — | — | 2.8% | Nov 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor... |
| CVE-2015-8037 | — | — | 2.8% | Nov 2, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor... |
| CVE-2015-8036 | — | — | 2.9% | Nov 2, 2015 | Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SS... |
| CVE-2015-6031 | — | — | 4.8% | Nov 2, 2015 | Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.201509... |
| CVE-2015-5534 | — | — | 2.3% | Nov 2, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the aut... |
| CVE-2015-5470 | — | — | 11.3% | Nov 2, 2015 | The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) ... |
| CVE-2015-5308 | — | — | 2.2% | Nov 2, 2015 | Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remot... |
| CVE-2015-5291 | — | — | 3.6% | Nov 2, 2015 | Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.... |
| CVE-2015-5210 | — | — | 4.1% | Nov 2, 2015 | Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sit... |
| CVE-2015-3270 | — | — | 2.7% | Nov 2, 2015 | Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via... |
| CVE-2015-3186 | — | — | 2.3% | Nov 2, 2015 | Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator user... |
| CVE-2015-1775 | — | — | 3.0% | Nov 2, 2015 | Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allo... |
| CVE-2015-6354 | — | — | 1.1% | Oct 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remo... |
| CVE-2015-6353 | — | — | 1.1% | Oct 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.3.1.5 and 5.4.x through ... |
| CVE-2015-6343 | — | — | 2.0% | Oct 31, 2015 | The SIP implementation in Cisco IOS 15.5(3)M on Cisco Unified Border Element (CUBE) devices allows remote attackers to c... |
| CVE-2015-6033 | — | — | 2.4% | Oct 31, 2015 | Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-t... |
| CVE-2015-6032 | — | — | 3.3% | Oct 31, 2015 | Qolsys IQ Panel (aka QOL) before 1.5.1 has hardcoded cryptographic keys, which allows remote attackers to create digital... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now