2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7836 | — | — | 0.9% | Oct 28, 2015 | Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for V... |
| CVE-2015-6494 | — | — | 1.7% | Oct 28, 2015 | Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 ... |
| CVE-2015-6493 | — | — | 1.3% | Oct 28, 2015 | Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 bu... |
| CVE-2015-6492 | HIGH | 7.5 | 4.4% | Oct 28, 2015 | Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to... |
| CVE-2015-6491 | — | — | 1.6% | Oct 28, 2015 | Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticate... |
| CVE-2015-6490 | CRITICAL | 9.8 | 7.0% | Oct 28, 2015 | Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN ... |
| CVE-2015-6488 | — | — | 2.8% | Oct 28, 2015 | Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 ... |
| CVE-2015-6486 | — | — | 4.3% | Oct 28, 2015 | SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 1... |
| CVE-2015-5713 | — | — | 2.1% | Oct 28, 2015 | Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6... |
| CVE-2015-5712 | — | — | 1.7% | Oct 28, 2015 | Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6... |
| CVE-2015-3973 | — | — | 1.5% | Oct 28, 2015 | Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote att... |
| CVE-2015-3972 | — | — | 2.9% | Oct 28, 2015 | The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, ... |
| CVE-2015-3971 | — | — | 1.6% | Oct 28, 2015 | The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows rem... |
| CVE-2015-3970 | — | — | 1.1% | Oct 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devi... |
| CVE-2015-3969 | — | — | 1.4% | Oct 28, 2015 | Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection informatio... |
| CVE-2015-3968 | — | — | 2.3% | Oct 28, 2015 | The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for rem... |
| CVE-2015-3967 | — | — | 0.6% | Oct 28, 2015 | Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attacke... |
| CVE-2015-7986 | — | — | 6.2% | Oct 27, 2015 | The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni... |
| CVE-2015-5262 | — | — | 19.3% | Oct 27, 2015 | http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.t... |
| CVE-2015-5240 | — | — | 1.0% | Oct 27, 2015 | Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the securit... |
| CVE-2015-5220 | — | — | 3.0% | Oct 27, 2015 | The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Se... |
| CVE-2015-5188 | — | — | 1.1% | Oct 27, 2015 | Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platf... |
| CVE-2015-5178 | — | — | 1.7% | Oct 27, 2015 | The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application S... |
| CVE-2015-3996 | — | — | 0.8% | Oct 27, 2015 | The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework be... |
| CVE-2015-6340 | — | — | 2.0% | Oct 27, 2015 | The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.6073... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now