2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-6460Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execut...
CVE-2015-6459Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET a...
CVE-2015-6456GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account...
CVE-2015-6297The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of...
CVE-2015-6296Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obt...
CVE-2015-6294Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (funct...
CVE-2015-3962Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data strea...
CVE-2015-7243Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly...
CVE-2015-6939Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to in...
CVE-2015-7239SQL injection vulnerability in the BP_FIND_JOBS_WITH_PROGRAM function module in SAP NetWeaver J2EE Engine 7.40 allows re...
CVE-2015-7238The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) config...
CVE-2015-7237Directory traversal vulnerability in the remote log viewing functionality in McAfee Agent (MA) 5.x before 5.0.2 allows r...
CVE-2015-5274rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary command...
CVE-2015-4638The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through ...
CVE-2015-5921WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-mid...
CVE-2015-5920The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-...
CVE-2015-5916The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information...
CVE-2015-5912The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection atte...
CVE-2015-5911Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have...
CVE-2015-5910IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attacke...
CVE-2015-5909IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows re...
CVE-2015-5907WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishand...
CVE-2015-5906The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of...
CVE-2015-5905Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafte...
CVE-2015-5904Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafte...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now