2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2851 | — | — | 0.8% | May 30, 2015 | client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change... |
| CVE-2015-1937 | — | — | 1.6% | May 30, 2015 | IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authenticatio... |
| CVE-2015-0193 | — | — | 0.7% | May 30, 2015 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.... |
| CVE-2015-0191 | — | — | — | May 30, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0191. Reason: This candidate is a duplicate of... |
| CVE-2015-0121 | — | — | 0.4% | May 30, 2015 | IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4... |
| CVE-2015-0758 | — | — | 1.6% | May 30, 2015 | The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via ... |
| CVE-2015-0747 | — | — | 1.8% | May 30, 2015 | Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies v... |
| CVE-2015-0745 | — | — | 1.9% | May 30, 2015 | Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently o... |
| CVE-2015-0744 | — | — | 3.4% | May 30, 2015 | Cisco DTA Control System (DTACS) 4.0.0.9 and Cisco Headend System Release allow remote attackers to cause a denial of se... |
| CVE-2015-0743 | — | — | 2.0% | May 30, 2015 | Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of ... |
| CVE-2015-0733 | — | — | 1.5% | May 30, 2015 | CRLF injection vulnerability in the HTTP Header Handler in Digital Broadband Delivery System in Cisco Headend System Rel... |
| CVE-2015-4069 | — | — | 4.4% | May 29, 2015 | The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credenti... |
| CVE-2015-4068 | CRITICAL | 9.1 | 63.6% | May 29, 2015 | Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive inform... |
| CVE-2015-4067 | — | — | 5.9% | May 29, 2015 | Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary... |
| CVE-2015-4060 | — | — | 4.8% | May 29, 2015 | Heap-based buffer overflow in the TermProxy (WLTermProxyService.exe) service in Wavelink ConnectPro allows remote attack... |
| CVE-2015-4059 | — | — | 4.8% | May 29, 2015 | Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote a... |
| CVE-2015-4047 | — | — | 9.6% | May 29, 2015 | racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and ... |
| CVE-2015-4032 | — | — | 2.3% | May 29, 2015 | projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary... |
| CVE-2015-4031 | — | — | 7.1% | May 29, 2015 | Directory traversal vulnerability in saveFile.jsp in the development installation in Visual Mining NetChart allows remot... |
| CVE-2015-3995 | — | — | 1.3% | May 29, 2015 | SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FRO... |
| CVE-2015-3994 | — | — | 1.2% | May 29, 2015 | The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) a... |
| CVE-2015-1833 | — | — | 51.5% | May 29, 2015 | XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.... |
| CVE-2015-0847 | — | — | 3.1% | May 29, 2015 | nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote atta... |
| CVE-2015-0757 | — | — | 2.4% | May 29, 2015 | The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session ... |
| CVE-2015-0756 | — | — | 0.7% | May 29, 2015 | Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a denial of service (... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now