2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8698 | — | — | 0.6% | Jun 29, 2016 | CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5... |
| CVE-2015-7473 | — | — | 0.3% | Jun 26, 2016 | runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restri... |
| CVE-2015-7988 | — | — | 4.8% | Jun 26, 2016 | The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary cod... |
| CVE-2015-7987 | — | — | 2.5% | Jun 26, 2016 | Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memo... |
| CVE-2015-6289 | — | — | 4.4% | Jun 23, 2016 | Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a deni... |
| CVE-2015-8289 | — | — | 2.2% | Jun 20, 2016 | The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 a... |
| CVE-2015-8288 | — | — | 1.9% | Jun 20, 2016 | NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded... |
| CVE-2015-7776 | — | — | 1.3% | Jun 19, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for rem... |
| CVE-2015-7462 | — | — | 0.2% | Jun 19, 2016 | IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords with... |
| CVE-2015-7775 | — | — | 0.8% | Jun 19, 2016 | Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary we... |
| CVE-2015-8914 | — | — | 4.2% | Jun 17, 2016 | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an int... |
| CVE-2015-8869 | — | — | 5.2% | Jun 13, 2016 | OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow a... |
| CVE-2015-8268 | — | — | 3.0% | Jun 10, 2016 | The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary ... |
| CVE-2015-1797 | — | — | — | Jun 9, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-8800 | HIGH | 7.3 | 1.4% | Jun 8, 2016 | Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical Syste... |
| CVE-2015-8799 | HIGH | 7.6 | 5.7% | Jun 8, 2016 | Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SE... |
| CVE-2015-8798 | HIGH | 8 | 2.5% | Jun 8, 2016 | Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SE... |
| CVE-2015-8157 | HIGH | 8.8 | 1.7% | Jun 8, 2016 | SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP)... |
| CVE-2015-7695 | — | — | 3.0% | Jun 7, 2016 | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attacke... |
| CVE-2015-7611 | — | — | 68.6% | Jun 7, 2016 | Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst... |
| CVE-2015-5723 | — | — | 0.4% | Jun 7, 2016 | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1... |
| CVE-2015-5261 | — | — | 0.5% | Jun 7, 2016 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations ... |
| CVE-2015-5260 | — | — | 0.6% | Jun 7, 2016 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory ... |
| CVE-2015-5231 | — | — | 0.4% | Jun 7, 2016 | The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obta... |
| CVE-2015-5228 | — | — | 0.4% | Jun 7, 2016 | The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now