2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2212 | — | — | — | Aug 3, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-5623. Reason: This candidate is a reservation ... |
| CVE-2015-5600 | HIGH | 8.1 | 9.3% | Aug 3, 2015 | The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processin... |
| CVE-2015-5537 | — | — | 1.1% | Aug 3, 2015 | The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padd... |
| CVE-2015-5352 | — | — | 5.4% | Aug 3, 2015 | The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks ... |
| CVE-2015-5084 | — | — | 0.4% | Aug 3, 2015 | The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly s... |
| CVE-2015-5618 | — | — | 1.7% | Aug 1, 2015 | Chiyu BF-630 and BF-630W fingerprint access-control devices allow remote attackers to bypass authentication and (1) read... |
| CVE-2015-4295 | — | — | 1.3% | Aug 1, 2015 | The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authe... |
| CVE-2015-4294 | — | — | 1.4% | Aug 1, 2015 | Cross-site scripting (XSS) vulnerability in Cisco IM and Presence Service before 10.5 MR1 allows remote attackers to inj... |
| CVE-2015-4292 | — | — | 1.4% | Aug 1, 2015 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Sol... |
| CVE-2015-4291 | — | — | 2.0% | Aug 1, 2015 | Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of se... |
| CVE-2015-4289 | — | — | 1.9% | Aug 1, 2015 | Directory traversal vulnerability in Cisco AnyConnect Secure Mobility Client 4.0(2049) allows remote head-end systems to... |
| CVE-2015-2890 | MEDIUM | 6 | 0.8% | Aug 1, 2015 | The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solut... |
| CVE-2015-2871 | — | — | 1.7% | Aug 1, 2015 | Chiyu BF-660C fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) mod... |
| CVE-2015-2870 | — | — | 1.2% | Aug 1, 2015 | Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows... |
| CVE-2015-1904 | — | — | 1.4% | Aug 1, 2015 | IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 throug... |
| CVE-2015-1492 | — | — | 1.7% | Aug 1, 2015 | Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local ... |
| CVE-2015-1491 | — | — | 1.6% | Aug 1, 2015 | SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU... |
| CVE-2015-1490 | — | — | 2.4% | Aug 1, 2015 | Directory traversal vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 1... |
| CVE-2015-1489 | — | — | 24.6% | Aug 1, 2015 | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat... |
| CVE-2015-1488 | — | — | 1.8% | Aug 1, 2015 | An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-... |
| CVE-2015-1487 | — | — | 47.3% | Aug 1, 2015 | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat... |
| CVE-2015-1486 | — | — | 64.5% | Aug 1, 2015 | The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t... |
| CVE-2015-1009 | — | — | 0.3% | Aug 1, 2015 | Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Pat... |
| CVE-2015-4293 | — | — | 1.8% | Jul 30, 2015 | The packet-reassembly implementation in Cisco IOS XE 3.13S and earlier allows remote attackers to cause a denial of serv... |
| CVE-2015-5477 | — | — | 90.9% | Jul 29, 2015 | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now