2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8666 | HIGH | 7.9 | 0.4% | Apr 11, 2017 | Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator. |
| CVE-2015-7260 | HIGH | 7.8 | 0.3% | Apr 10, 2017 | Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable f... |
| CVE-2015-6028 | HIGH | 8.8 | 1.1% | Apr 10, 2017 | Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter. |
| CVE-2015-2889 | HIGH | 8.8 | 1.7% | Apr 10, 2017 | Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a... |
| CVE-2015-8026 | HIGH | 7.8 | 4.5% | Mar 27, 2017 | Heap-based buffer overflow in the verify_vbr_checksum function in exfatfsck in exfat-utils before 1.2.1 allows remote at... |
| CVE-2015-3884 | HIGH | 8.8 | 14.4% | Mar 17, 2017 | Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) ... |
| CVE-2015-8994 | HIGH | 7.5 | 2.9% | Mar 2, 2017 | An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache e... |
| CVE-2015-4057 | HIGH | 7.5 | 1.5% | Feb 21, 2017 | The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon ... |
| CVE-2015-8971 | HIGH | 7.8 | 1.1% | Jan 23, 2017 | Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window titl... |
| CVE-2015-8854 | HIGH | 7.5 | 4.3% | Jan 23, 2017 | The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecif... |
| CVE-2015-8315 | HIGH | 7.5 | 6.8% | Jan 23, 2017 | The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long versi... |
| CVE-2015-7848 | HIGH | 7.5 | 6.1% | Jan 6, 2017 | An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a spec... |
| CVE-2015-8743 | HIGH | 7.1 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It co... |
| CVE-2015-8967 | HIGH | 7.8 | 0.8% | Dec 8, 2016 | arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protec... |
| CVE-2015-8963 | HIGH | 7 | 1.4% | Nov 16, 2016 | Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a d... |
| CVE-2015-8962 | HIGH | 7.3 | 1.8% | Nov 16, 2016 | Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows loc... |
| CVE-2015-8961 | HIGH | 7.8 | 2.0% | Nov 16, 2016 | The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain priv... |
| CVE-2015-8968 | HIGH | 8.8 | 5.2% | Nov 3, 2016 | git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a use... |
| CVE-2015-3288 | HIGH | 7.8 | 0.5% | Oct 16, 2016 | mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or ... |
| CVE-2015-8955 | HIGH | 7.3 | 0.2% | Oct 10, 2016 | arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges o... |
| CVE-2015-0572 | HIGH | 7 | 0.3% | Oct 10, 2016 | Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux... |
| CVE-2015-8960 | HIGH | 8.1 | 1.9% | Sep 21, 2016 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values fo... |
| CVE-2015-0568 | HIGH | 7.8 | 0.9% | Aug 7, 2016 | Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driv... |
| CVE-2015-5738 | HIGH | 7.5 | 2.4% | Jul 26, 2016 | The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on L... |
| CVE-2015-8800 | HIGH | 7.3 | 1.4% | Jun 8, 2016 | Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical Syste... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now