2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8635 | — | — | 26.6% | Dec 28, 2015 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and ... |
| CVE-2015-8634 | — | — | 26.6% | Dec 28, 2015 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and ... |
| CVE-2015-8460 | — | — | 5.2% | Dec 28, 2015 | Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on ... |
| CVE-2015-8459 | — | — | 6.1% | Dec 28, 2015 | Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on ... |
| CVE-2015-6852 | — | — | 2.0% | Dec 28, 2015 | Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote... |
| CVE-2015-6850 | — | — | 0.5% | Dec 28, 2015 | EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allow... |
| CVE-2015-8569 | — | — | 0.5% | Dec 28, 2015 | The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not veri... |
| CVE-2015-8374 | — | — | 0.5% | Dec 28, 2015 | fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obta... |
| CVE-2015-7990 | — | — | 0.3% | Dec 28, 2015 | Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to c... |
| CVE-2015-7885 | — | — | 0.4% | Dec 28, 2015 | The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a... |
| CVE-2015-7884 | — | — | 0.4% | Dec 28, 2015 | The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initi... |
| CVE-2015-7509 | — | — | 0.4% | Dec 28, 2015 | fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (syste... |
| CVE-2015-7783 | — | — | 1.0% | Dec 27, 2015 | Cross-site scripting (XSS) vulnerability in Let's PHP! p++BBS before 4.10 allows remote attackers to inject arbitrary we... |
| CVE-2015-7665 | — | — | 1.6% | Dec 27, 2015 | Tails before 1.7 includes the wget program but does not prevent automatic fallback from passive FTP to active FTP, which... |
| CVE-2015-6538 | — | — | 1.9% | Dec 27, 2015 | The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attac... |
| CVE-2015-6537 | — | — | 1.5% | Dec 27, 2015 | SQL injection vulnerability in the login page in Epiphany Cardio Server 3.3 allows remote attackers to execute arbitrary... |
| CVE-2015-8263 | — | — | 1.8% | Dec 27, 2015 | NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it eas... |
| CVE-2015-8262 | — | — | 1.1% | Dec 27, 2015 | Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in t... |
| CVE-2015-8254 | — | — | 0.4% | Dec 27, 2015 | The Frontel protocol before 3 on RSI Video Technologies Videofied devices does not use integrity protection, which makes... |
| CVE-2015-8253 | — | — | 0.7% | Dec 27, 2015 | The Frontel protocol before 3 on RSI Video Technologies Videofied devices sets up AES encryption but sends all traffic i... |
| CVE-2015-8252 | — | — | 1.4% | Dec 27, 2015 | The Frontel protocol before 3 on RSI Video Technologies Videofied devices sends a cleartext serial number, which allows ... |
| CVE-2015-6005 | — | — | 1.9% | Dec 27, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to injec... |
| CVE-2015-6004 | — | — | 2.3% | Dec 27, 2015 | Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary ... |
| CVE-2015-8669 | — | — | 2.2% | Dec 26, 2015 | libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 ... |
| CVE-2015-6409 | — | — | 1.3% | Dec 26, 2015 | Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade atta... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now