2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8279 | — | — | 51.4% | Jan 15, 2016 | Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an un... |
| CVE-2015-6467 | — | — | 3.8% | Jan 15, 2016 | Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin. |
| CVE-2015-6423 | — | — | 1.2% | Jan 15, 2016 | The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remo... |
| CVE-2015-6336 | — | — | 1.4% | Jan 15, 2016 | Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, w... |
| CVE-2015-6323 | — | — | 3.0% | Jan 15, 2016 | The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before ... |
| CVE-2015-6320 | — | — | 1.9% | Jan 15, 2016 | The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attack... |
| CVE-2015-6314 | — | — | 3.0% | Jan 15, 2016 | Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow re... |
| CVE-2015-5007 | — | — | 0.9% | Jan 15, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and... |
| CVE-2015-3948 | — | — | 1.0% | Jan 15, 2016 | Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject a... |
| CVE-2015-3947 | — | — | 1.7% | Jan 15, 2016 | SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL... |
| CVE-2015-3946 | — | — | 0.9% | Jan 15, 2016 | Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the ... |
| CVE-2015-3943 | — | — | 1.8% | Jan 15, 2016 | Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project acco... |
| CVE-2015-8605 | — | — | 76.4% | Jan 14, 2016 | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of servic... |
| CVE-2015-8607 | — | — | 3.1% | Jan 13, 2016 | The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve th... |
| CVE-2015-8466 | — | — | 2.0% | Jan 13, 2016 | Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date heade... |
| CVE-2015-6117 | — | — | 7.0% | Jan 13, 2016 | Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass inten... |
| CVE-2015-8769 | — | — | 1.1% | Jan 12, 2016 | SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecifi... |
| CVE-2015-8673 | — | — | 0.2% | Jan 12, 2016 | Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not ... |
| CVE-2015-8672 | — | — | 0.9% | Jan 12, 2016 | The presentation transmission permission management mechanism in Huawei TE30, TE40, TE50, and TE60 multimedia video conf... |
| CVE-2015-8611 | — | — | 3.2% | Jan 12, 2016 | BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000... |
| CVE-2015-8396 | — | — | 16.8% | Jan 12, 2016 | Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx... |
| CVE-2015-7759 | — | — | 1.5% | Jan 12, 2016 | BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtua... |
| CVE-2015-7393 | — | — | 0.3% | Jan 12, 2016 | dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP... |
| CVE-2015-8659 | — | — | 4.1% | Jan 12, 2016 | The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a ... |
| CVE-2015-8603 | — | — | 1.2% | Jan 12, 2016 | Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web scr... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now