2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6460 | — | — | 6.2% | Sep 18, 2015 | Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execut... |
| CVE-2015-6459 | — | — | 3.1% | Sep 18, 2015 | Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET a... |
| CVE-2015-6456 | — | — | 3.8% | Sep 18, 2015 | GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account... |
| CVE-2015-6297 | — | — | 2.4% | Sep 18, 2015 | The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of... |
| CVE-2015-6296 | — | — | 0.4% | Sep 18, 2015 | Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obt... |
| CVE-2015-6294 | — | — | 0.8% | Sep 18, 2015 | Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (funct... |
| CVE-2015-3962 | — | — | 1.2% | Sep 18, 2015 | Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data strea... |
| CVE-2015-7243 | — | — | 58.3% | Sep 18, 2015 | Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly... |
| CVE-2015-6939 | — | — | 2.9% | Sep 18, 2015 | Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to in... |
| CVE-2015-7239 | — | — | 2.2% | Sep 18, 2015 | SQL injection vulnerability in the BP_FIND_JOBS_WITH_PROGRAM function module in SAP NetWeaver J2EE Engine 7.40 allows re... |
| CVE-2015-7238 | — | — | 0.3% | Sep 18, 2015 | The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) config... |
| CVE-2015-7237 | — | — | 2.8% | Sep 18, 2015 | Directory traversal vulnerability in the remote log viewing functionality in McAfee Agent (MA) 5.x before 5.0.2 allows r... |
| CVE-2015-5274 | — | — | 2.1% | Sep 18, 2015 | rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary command... |
| CVE-2015-4638 | — | — | 1.7% | Sep 18, 2015 | The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through ... |
| CVE-2015-5921 | — | — | 1.3% | Sep 18, 2015 | WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-mid... |
| CVE-2015-5920 | — | — | 1.2% | Sep 18, 2015 | The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-... |
| CVE-2015-5916 | — | — | 1.5% | Sep 18, 2015 | The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information... |
| CVE-2015-5912 | — | — | 1.7% | Sep 18, 2015 | The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection atte... |
| CVE-2015-5911 | — | — | 2.0% | Sep 18, 2015 | Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have... |
| CVE-2015-5910 | — | — | 0.8% | Sep 18, 2015 | IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attacke... |
| CVE-2015-5909 | — | — | 1.9% | Sep 18, 2015 | IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows re... |
| CVE-2015-5907 | — | — | 0.8% | Sep 18, 2015 | WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishand... |
| CVE-2015-5906 | — | — | 2.0% | Sep 18, 2015 | The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of... |
| CVE-2015-5905 | — | — | 1.9% | Sep 18, 2015 | Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafte... |
| CVE-2015-5904 | — | — | 1.4% | Sep 18, 2015 | Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafte... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now