2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8276LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC fil...
CVE-2015-8275LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC...
CVE-2015-8258AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v...
CVE-2015-8255AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
CVE-2015-7292Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-0...
CVE-2015-7275Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
CVE-2015-7274Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrati...
CVE-2015-7273Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
CVE-2015-7272Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a den...
CVE-2015-7271Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
CVE-2015-7270Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
CVE-2015-7265Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijac...
CVE-2015-7264The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking a...
CVE-2015-7263The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ...
CVE-2015-7260HIGH7.8Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable f...
CVE-2015-6035Opsview before 2015-11-06 has XSS via SNMP.
CVE-2015-6028HIGH8.8Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
CVE-2015-6027MEDIUM6.1Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
CVE-2015-6021Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
CVE-2015-2889HIGH8.8Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a...
CVE-2015-2888CRITICAL9.8Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the...
CVE-2015-2887iBaby M3S has a password of admin for the backdoor admin account.
CVE-2015-2886iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.
CVE-2015-2885Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user accou...
CVE-2015-2884Philips In.Sight B120/37 allows remote attackers to obtain sensitive information via a direct request, related to yoics....

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now