2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7297 | — | — | 100.0% | Oct 29, 2015 | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un... |
| CVE-2015-5955 | — | — | 1.1% | Oct 29, 2015 | ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instan... |
| CVE-2015-5285 | — | — | 6.0% | Oct 29, 2015 | CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc... |
| CVE-2015-3230 | — | — | 2.6% | Oct 29, 2015 | 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference wh... |
| CVE-2015-5292 | — | — | 3.7% | Oct 29, 2015 | Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Servic... |
| CVE-2015-6006 | — | — | 3.7% | Oct 29, 2015 | The AddUserFinding implementation in Medicomp MEDCIN Engine 2.22.20153.x before 2.22.20153.226 might allow remote attack... |
| CVE-2015-5671 | — | — | 1.4% | Oct 29, 2015 | Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to bypass intended access restrictions and read arbi... |
| CVE-2015-5670 | — | — | 1.2% | Oct 29, 2015 | Cross-site scripting (XSS) vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to injec... |
| CVE-2015-5669 | — | — | 2.0% | Oct 29, 2015 | Techno Project Japan Enisys Gw before 1.4.1 allows remote authenticated users to write to arbitrary files and consequent... |
| CVE-2015-5668 | — | — | 1.3% | Oct 29, 2015 | SQL injection vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to execute arbitrary ... |
| CVE-2015-5040 | — | — | 3.3% | Oct 29, 2015 | Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attac... |
| CVE-2015-4997 | — | — | 2.0% | Oct 29, 2015 | IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted requ... |
| CVE-2015-4994 | — | — | 3.3% | Oct 29, 2015 | Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attac... |
| CVE-2015-2901 | — | — | 3.2% | Oct 29, 2015 | Multiple stack-based buffer overflows in Medicomp MEDCIN Engine 2.22.20142.166 might allow remote attackers to execute a... |
| CVE-2015-2900 | — | — | 3.1% | Oct 29, 2015 | The AddUserFinding add_userfinding2 function in Medicomp MEDCIN Engine before 2.22.20153.226 allows remote attackers to ... |
| CVE-2015-2899 | — | — | 2.6% | Oct 29, 2015 | Heap-based buffer overflow in the QualifierList retrieve_qualifier_list function in Medicomp MEDCIN Engine before 2.22.2... |
| CVE-2015-2898 | — | — | 3.2% | Oct 29, 2015 | Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to ex... |
| CVE-2015-7649 | — | — | 3.8% | Oct 28, 2015 | Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denial of service (memory... |
| CVE-2015-6034 | — | — | 0.3% | Oct 28, 2015 | EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to ga... |
| CVE-2015-7904 | — | — | 2.8% | Oct 28, 2015 | Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 al... |
| CVE-2015-7903 | — | — | 1.3% | Oct 28, 2015 | SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote... |
| CVE-2015-7902 | — | — | 3.5% | Oct 28, 2015 | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed... |
| CVE-2015-7901 | — | — | 3.3% | Oct 28, 2015 | Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut... |
| CVE-2015-7900 | — | — | 2.9% | Oct 28, 2015 | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive ... |
| CVE-2015-7873 | — | — | 2.6% | Oct 28, 2015 | The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now