2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7568 | — | — | 4.1% | Apr 24, 2017 | SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the a... |
| CVE-2015-7247 | — | — | 10.2% | Apr 24, 2017 | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and... |
| CVE-2015-7246 | — | — | 14.3% | Apr 24, 2017 | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou... |
| CVE-2015-7245 | — | — | 45.5% | Apr 24, 2017 | Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot... |
| CVE-2015-8110 | — | — | 0.5% | Apr 24, 2017 | Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by nav... |
| CVE-2015-8109 | — | — | 0.4% | Apr 24, 2017 | Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by mak... |
| CVE-2015-1522 | — | — | 1.8% | Apr 24, 2017 | analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which all... |
| CVE-2015-1521 | — | — | 1.8% | Apr 24, 2017 | analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows... |
| CVE-2015-0107 | — | — | 6.0% | Apr 24, 2017 | IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database ... |
| CVE-2015-0104 | — | — | 6.8% | Apr 24, 2017 | IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database ... |
| CVE-2015-8285 | — | — | 5.5% | Apr 20, 2017 | The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service. |
| CVE-2015-8959 | MEDIUM | 6.5 | 3.4% | Apr 20, 2017 | coders/dds.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (CPU consumption) v... |
| CVE-2015-8958 | — | — | 2.9% | Apr 20, 2017 | coders/sun.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (out-of-bounds read... |
| CVE-2015-8957 | — | — | 3.0% | Apr 20, 2017 | Buffer overflow in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (application cra... |
| CVE-2015-8256 | — | — | 50.8% | Apr 17, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. |
| CVE-2015-6568 | — | — | 10.5% | Apr 14, 2017 | Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/... |
| CVE-2015-6567 | — | — | 10.8% | Apr 14, 2017 | Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/... |
| CVE-2015-8356 | — | — | 2.7% | Apr 14, 2017 | Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated u... |
| CVE-2015-8619 | HIGH | 7.5 | 3.9% | Apr 13, 2017 | The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write an... |
| CVE-2015-8567 | HIGH | 7.7 | 5.6% | Apr 13, 2017 | Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). |
| CVE-2015-8345 | MEDIUM | 6.5 | 0.4% | Apr 13, 2017 | The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash an... |
| CVE-2015-4646 | HIGH | 7.5 | 6.9% | Apr 13, 2017 | (1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attack... |
| CVE-2015-2947 | — | — | 1.5% | Apr 13, 2017 | KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound ne... |
| CVE-2015-8780 | — | — | 0.6% | Apr 13, 2017 | Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury. |
| CVE-2015-8864 | — | — | 2.7% | Apr 13, 2017 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attacker... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now