2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8941 | — | — | 0.5% | Aug 6, 2016 | drivers/media/platform/msm/camera_v2/isp/msm_isp_axi_util.c in the Qualcomm components in Android before 2016-08-05 on N... |
| CVE-2015-8940 | — | — | 0.5% | Aug 6, 2016 | Integer overflow in sound/soc/msm/qdsp6v2/q6lsm.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 dev... |
| CVE-2015-8939 | — | — | 0.5% | Aug 6, 2016 | drivers/video/msm/mdp4_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not... |
| CVE-2015-8938 | — | — | 0.5% | Aug 6, 2016 | The MSM camera driver in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices does not validate input... |
| CVE-2015-8937 | — | — | 0.5% | Aug 6, 2016 | drivers/char/diag/diagchar_core.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 6, and 7 (2013) de... |
| CVE-2015-8945 | — | — | 0.4% | Aug 5, 2016 | openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the... |
| CVE-2015-5738 | HIGH | 7.5 | 2.4% | Jul 26, 2016 | The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on L... |
| CVE-2015-8946 | — | — | 0.4% | Jul 22, 2016 | ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot w... |
| CVE-2015-8947 | — | — | 2.5% | Jul 19, 2016 | hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-re... |
| CVE-2015-1977 | — | — | 1.7% | Jul 15, 2016 | Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-I... |
| CVE-2015-8808 | — | — | 1.5% | Jul 13, 2016 | The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (... |
| CVE-2015-3192 | — | — | 5.3% | Jul 12, 2016 | Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is ... |
| CVE-2015-8893 | — | — | 0.4% | Jul 11, 2016 | app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attacke... |
| CVE-2015-8892 | — | — | 0.6% | Jul 11, 2016 | platform/msm_shared/boot_verifier.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5X and 6P devices a... |
| CVE-2015-8891 | — | — | 0.5% | Jul 11, 2016 | Multiple integer overflows in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7... |
| CVE-2015-8890 | — | — | 0.5% | Jul 11, 2016 | platform/msm_shared/partition_parser.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) d... |
| CVE-2015-8889 | — | — | 0.5% | Jul 11, 2016 | The aboot implementation in the Qualcomm components in Android before 2016-07-05 on Nexus 6P devices omits the recovery ... |
| CVE-2015-8888 | — | — | 0.5% | Jul 11, 2016 | Integer overflow in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows ... |
| CVE-2015-0899 | — | — | 21.4% | Jul 4, 2016 | The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended a... |
| CVE-2015-5664 | — | — | 1.0% | Jul 3, 2016 | Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbi... |
| CVE-2015-7029 | — | — | 3.9% | Jul 3, 2016 | Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attacker... |
| CVE-2015-6931 | — | — | 0.8% | Jul 3, 2016 | Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U... |
| CVE-2015-8801 | — | — | 0.3% | Jun 30, 2016 | Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass inte... |
| CVE-2015-8899 | — | — | 2.4% | Jun 30, 2016 | Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address tha... |
| CVE-2015-8699 | — | — | 1.8% | Jun 29, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 be... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now