2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2886 | — | — | 1.3% | Apr 10, 2017 | iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service. |
| CVE-2015-2885 | — | — | 1.4% | Apr 10, 2017 | Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user accou... |
| CVE-2015-2884 | — | — | 1.5% | Apr 10, 2017 | Philips In.Sight B120/37 allows remote attackers to obtain sensitive information via a direct request, related to yoics.... |
| CVE-2015-2883 | — | — | 0.5% | Apr 10, 2017 | Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to devi... |
| CVE-2015-2882 | — | — | 1.6% | Apr 10, 2017 | Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoo... |
| CVE-2015-2881 | — | — | 1.6% | Apr 10, 2017 | Gynoii has a password of guest for the backdoor guest account and a password of 12345 for the backdoor admin account. |
| CVE-2015-2880 | — | — | 1.2% | Apr 10, 2017 | TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account. |
| CVE-2015-4673 | — | — | 0.8% | Apr 6, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arb... |
| CVE-2015-9019 | — | — | 2.4% | Apr 5, 2017 | In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, whi... |
| CVE-2015-4680 | — | — | 1.8% | Apr 5, 2017 | FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates. |
| CVE-2015-1612 | — | — | 2.1% | Apr 4, 2017 | OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow... |
| CVE-2015-1611 | — | — | 2.1% | Apr 4, 2017 | OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow... |
| CVE-2015-8671 | — | — | 0.9% | Apr 2, 2017 | Huawei LogCenter V100R001C10 could allow an authenticated attacker to tamper with requests using a tool and submit a req... |
| CVE-2015-8670 | — | — | 0.6% | Apr 2, 2017 | Huawei LogCenter V100R001C10 could allow an authenticated attacker to add abnormal device information to the log collect... |
| CVE-2015-7847 | — | — | 0.2% | Apr 2, 2017 | Huawei MBB (Mobile Broadband) product E3272s with software versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00 h... |
| CVE-2015-7844 | — | — | 0.7% | Apr 2, 2017 | Huawei FusionAccess with software V100R005C10,V100R005C20 could allow attackers to craft and send a malformed HDP protoc... |
| CVE-2015-2246 | — | — | 0.5% | Apr 2, 2017 | The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the... |
| CVE-2015-4624 | — | — | 37.0% | Mar 31, 2017 | Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens. |
| CVE-2015-8234 | — | — | 1.2% | Mar 29, 2017 | The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification pr... |
| CVE-2015-4556 | — | — | 2.1% | Mar 29, 2017 | The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a ... |
| CVE-2015-8764 | — | — | 1.1% | Mar 27, 2017 | Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow. |
| CVE-2015-8763 | — | — | 1.2% | Mar 27, 2017 | The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) ... |
| CVE-2015-8762 | — | — | 1.6% | Mar 27, 2017 | The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer de... |
| CVE-2015-8010 | — | — | 1.5% | Mar 27, 2017 | Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga bef... |
| CVE-2015-0864 | — | — | 0.8% | Mar 27, 2017 | Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to o... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now