2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7923 | — | — | 1.2% | Jan 30, 2016 | Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easi... |
| CVE-2015-8773 | — | — | 1.2% | Jan 29, 2016 | Stack-based buffer overflow in McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows attackers... |
| CVE-2015-8772 | — | — | 1.5% | Jan 29, 2016 | McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive informat... |
| CVE-2015-7521 | — | — | 6.1% | Jan 29, 2016 | The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger ... |
| CVE-2015-8794 | — | — | 2.1% | Jan 29, 2016 | Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before ... |
| CVE-2015-8793 | — | — | 1.4% | Jan 29, 2016 | Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 ... |
| CVE-2015-8792 | — | — | 1.5% | Jan 29, 2016 | The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensiti... |
| CVE-2015-8791 | — | — | 1.3% | Jan 29, 2016 | The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensit... |
| CVE-2015-8790 | — | — | 1.8% | Jan 29, 2016 | The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sens... |
| CVE-2015-8789 | — | — | 2.1% | Jan 29, 2016 | Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers... |
| CVE-2015-8770 | — | — | 22.2% | Jan 29, 2016 | Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before... |
| CVE-2015-7464 | — | — | 1.3% | Jan 29, 2016 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-C... |
| CVE-2015-6421 | — | — | 1.9% | Jan 27, 2016 | cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) de... |
| CVE-2015-6319 | — | — | 2.7% | Jan 27, 2016 | SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to exe... |
| CVE-2015-8618 | — | — | 2.6% | Jan 27, 2016 | The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces i... |
| CVE-2015-7488 | — | — | 0.4% | Jan 27, 2016 | IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows... |
| CVE-2015-7487 | — | — | 0.3% | Jan 27, 2016 | IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo... |
| CVE-2015-7439 | — | — | 0.8% | Jan 27, 2016 | Cross-site scripting (XSS) vulnerability in InfoSphere Data Architect (IDA), as distributed in IBM Rational Software Arc... |
| CVE-2015-8379 | — | — | 1.4% | Jan 26, 2016 | CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method pa... |
| CVE-2015-6337 | — | — | 1.0% | Jan 26, 2016 | Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-E... |
| CVE-2015-7417 | — | — | 1.1% | Jan 23, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, a... |
| CVE-2015-6317 | — | — | 1.5% | Jan 23, 2016 | Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access... |
| CVE-2015-6925 | — | — | 2.7% | Jan 22, 2016 | wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or tra... |
| CVE-2015-6015 | — | — | 8.4% | Jan 22, 2016 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.... |
| CVE-2015-6014 | — | — | 8.4% | Jan 22, 2016 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now