2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-7836Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for V...
CVE-2015-6494Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 ...
CVE-2015-6493Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 bu...
CVE-2015-6492HIGH7.5Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to...
CVE-2015-6491Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticate...
CVE-2015-6490CRITICAL9.8Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN ...
CVE-2015-6488Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 ...
CVE-2015-6486SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 1...
CVE-2015-5713Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6...
CVE-2015-5712Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6...
CVE-2015-3973Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote att...
CVE-2015-3972The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, ...
CVE-2015-3971The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows rem...
CVE-2015-3970Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devi...
CVE-2015-3969Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection informatio...
CVE-2015-3968The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for rem...
CVE-2015-3967Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attacke...
CVE-2015-7986The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni...
CVE-2015-5262http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.t...
CVE-2015-5240Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the securit...
CVE-2015-5220The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Se...
CVE-2015-5188Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platf...
CVE-2015-5178The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application S...
CVE-2015-3996The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework be...
CVE-2015-6340The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.6073...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now