2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8400 | — | — | 2.0% | Jan 12, 2016 | The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers t... |
| CVE-2015-8337 | — | — | 0.8% | Jan 12, 2016 | The HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B220SP01, GRA-CL00 before GRA-CL00C92B220, ... |
| CVE-2015-8306 | — | — | 1.1% | Jan 12, 2016 | Buffer overflow in the HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GR... |
| CVE-2015-8098 | — | — | 4.7% | Jan 12, 2016 | F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cau... |
| CVE-2015-8088 | — | — | 3.8% | Jan 12, 2016 | Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7... |
| CVE-2015-7548 | — | — | 1.8% | Jan 12, 2016 | OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instance... |
| CVE-2015-7242 | — | — | 1.5% | Jan 12, 2016 | Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote att... |
| CVE-2015-5471 | — | — | 32.7% | Jan 12, 2016 | Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo... |
| CVE-2015-4703 | — | — | 2.9% | Jan 12, 2016 | Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows ... |
| CVE-2015-4671 | — | — | 1.5% | Jan 12, 2016 | Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web scri... |
| CVE-2015-8335 | — | — | 0.7% | Jan 11, 2016 | Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated user... |
| CVE-2015-8333 | — | — | 0.8% | Jan 11, 2016 | The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authentic... |
| CVE-2015-8331 | — | — | 0.8% | Jan 11, 2016 | The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly inval... |
| CVE-2015-8231 | — | — | 1.0% | Jan 11, 2016 | Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established ses... |
| CVE-2015-8230 | — | — | 1.0% | Jan 11, 2016 | Memory leak in Huawei eSpace 8950 IP phones with software before V200R003C00SPC300 allows remote attackers to cause a de... |
| CVE-2015-7706 | — | — | 1.5% | Jan 11, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to ... |
| CVE-2015-6566 | — | — | 0.4% | Jan 11, 2016 | zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symli... |
| CVE-2015-7399 | — | — | 1.9% | Jan 11, 2016 | IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 befor... |
| CVE-2015-7024 | — | — | 0.4% | Jan 11, 2016 | Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intended Gatekeeper restri... |
| CVE-2015-6980 | — | — | 0.4% | Jan 11, 2016 | Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to g... |
| CVE-2015-7466 | — | — | 0.8% | Jan 10, 2016 | Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote aut... |
| CVE-2015-7465 | — | — | 0.5% | Jan 10, 2016 | Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 ... |
| CVE-2015-7397 | — | — | 1.8% | Jan 10, 2016 | Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 ... |
| CVE-2015-7116 | — | — | 2.1% | Jan 10, 2016 | libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive in... |
| CVE-2015-7115 | — | — | 2.1% | Jan 10, 2016 | libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive in... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now