2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1838 | — | — | 0.4% | Apr 13, 2017 | modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. |
| CVE-2015-7564 | — | — | 3.4% | Apr 12, 2017 | Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co... |
| CVE-2015-7562 | — | — | 1.8% | Apr 12, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbi... |
| CVE-2015-7893 | — | — | 7.4% | Apr 11, 2017 | SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS... |
| CVE-2015-7826 | — | — | 1.1% | Apr 10, 2017 | botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers t... |
| CVE-2015-7825 | — | — | 1.0% | Apr 10, 2017 | botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service ... |
| CVE-2015-7824 | — | — | 1.7% | Apr 10, 2017 | botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle att... |
| CVE-2015-8378 | — | — | 1.2% | Apr 10, 2017 | In KeePassX before 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allow... |
| CVE-2015-8276 | — | — | 0.8% | Apr 10, 2017 | LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC fil... |
| CVE-2015-8275 | — | — | 0.6% | Apr 10, 2017 | LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC... |
| CVE-2015-8258 | — | — | 8.8% | Apr 10, 2017 | AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v... |
| CVE-2015-8255 | — | — | 2.2% | Apr 10, 2017 | AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. |
| CVE-2015-7292 | — | — | 1.9% | Apr 10, 2017 | Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-0... |
| CVE-2015-7275 | — | — | 1.2% | Apr 10, 2017 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS. |
| CVE-2015-7274 | — | — | 2.0% | Apr 10, 2017 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrati... |
| CVE-2015-7273 | — | — | 1.4% | Apr 10, 2017 | Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE. |
| CVE-2015-7272 | — | — | 2.7% | Apr 10, 2017 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a den... |
| CVE-2015-7271 | — | — | 2.7% | Apr 10, 2017 | Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo. |
| CVE-2015-7270 | — | — | 1.1% | Apr 10, 2017 | Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal. |
| CVE-2015-7265 | — | — | 1.2% | Apr 10, 2017 | Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijac... |
| CVE-2015-7264 | — | — | 1.2% | Apr 10, 2017 | The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking a... |
| CVE-2015-7263 | — | — | 1.2% | Apr 10, 2017 | The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ... |
| CVE-2015-6035 | — | — | 0.7% | Apr 10, 2017 | Opsview before 2015-11-06 has XSS via SNMP. |
| CVE-2015-6021 | — | — | 1.1% | Apr 10, 2017 | Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response. |
| CVE-2015-2887 | — | — | 1.4% | Apr 10, 2017 | iBaby M3S has a password of admin for the backdoor admin account. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now