2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-7564——Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co...
CVE-2015-7562——Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbi...
CVE-2015-7893——SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS...
CVE-2015-7826——botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers t...
CVE-2015-7825——botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service ...
CVE-2015-7824——botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle att...
CVE-2015-8378——In KeePassX before 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allow...
CVE-2015-8276——LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC fil...
CVE-2015-8275——LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC...
CVE-2015-8258——AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v...
CVE-2015-8255——AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
CVE-2015-7292——Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-0...
CVE-2015-7275——Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
CVE-2015-7274——Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrati...
CVE-2015-7273——Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
CVE-2015-7272——Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a den...
CVE-2015-7271——Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
CVE-2015-7270——Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
CVE-2015-7265——Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijac...
CVE-2015-7264——The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking a...
CVE-2015-7263——The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ...
CVE-2015-6035——Opsview before 2015-11-06 has XSS via SNMP.
CVE-2015-6021——Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
CVE-2015-2887——iBaby M3S has a password of admin for the backdoor admin account.
CVE-2015-2886——iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now