2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8284 | — | — | 4.2% | Apr 13, 2017 | SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions. |
| CVE-2015-8283 | — | — | 6.8% | Apr 13, 2017 | Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00. |
| CVE-2015-8282 | — | — | 6.6% | Apr 13, 2017 | SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account. |
| CVE-2015-8272 | — | — | 2.7% | Apr 13, 2017 | RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash). |
| CVE-2015-8271 | — | — | 5.9% | Apr 13, 2017 | The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code. |
| CVE-2015-8270 | — | — | 3.2% | Apr 13, 2017 | The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (inva... |
| CVE-2015-8223 | — | — | 0.2% | Apr 13, 2017 | Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B85, and P8 ALE-UL00 before ALE-UL00B211 allows local users ... |
| CVE-2015-8107 | — | — | 2.9% | Apr 13, 2017 | Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code. |
| CVE-2015-7740 | — | — | 0.2% | Apr 13, 2017 | Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users ... |
| CVE-2015-7565 | — | — | 0.8% | Apr 13, 2017 | Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1... |
| CVE-2015-6674 | — | — | 2.3% | Apr 13, 2017 | Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for j... |
| CVE-2015-1839 | — | — | 0.4% | Apr 13, 2017 | modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. |
| CVE-2015-1838 | — | — | 0.4% | Apr 13, 2017 | modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. |
| CVE-2015-7564 | — | — | 3.4% | Apr 12, 2017 | Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co... |
| CVE-2015-7563 | HIGH | 8.8 | 3.1% | Apr 12, 2017 | Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the aut... |
| CVE-2015-7562 | — | — | 1.8% | Apr 12, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbi... |
| CVE-2015-8666 | HIGH | 7.9 | 0.4% | Apr 11, 2017 | Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator. |
| CVE-2015-8613 | MEDIUM | 6.5 | 0.4% | Apr 11, 2017 | Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulati... |
| CVE-2015-8568 | MEDIUM | 6.5 | 0.5% | Apr 11, 2017 | Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to caus... |
| CVE-2015-8504 | MEDIUM | 6.5 | 3.1% | Apr 11, 2017 | Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic excep... |
| CVE-2015-7893 | — | — | 7.4% | Apr 11, 2017 | SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS... |
| CVE-2015-7826 | — | — | 1.1% | Apr 10, 2017 | botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers t... |
| CVE-2015-7825 | — | — | 1.0% | Apr 10, 2017 | botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service ... |
| CVE-2015-7824 | — | — | 1.7% | Apr 10, 2017 | botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle att... |
| CVE-2015-8378 | — | — | 1.2% | Apr 10, 2017 | In KeePassX before 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allow... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now