2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1350 | MEDIUM | 5.5 | 0.5% | May 2, 2016 | The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that undersp... |
| CVE-2015-8325 | HIGH | 7.8 | 0.6% | May 1, 2016 | The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is... |
| CVE-2015-8845 | — | — | 0.4% | Apr 27, 2016 | The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms do... |
| CVE-2015-8844 | — | — | 0.4% | Apr 27, 2016 | The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the ... |
| CVE-2015-8816 | MEDIUM | 6.8 | 0.5% | Apr 27, 2016 | The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-in... |
| CVE-2015-8812 | CRITICAL | 9.8 | 14.3% | Apr 27, 2016 | drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which ... |
| CVE-2015-7515 | MEDIUM | 4.6 | 1.8% | Apr 27, 2016 | The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at... |
| CVE-2015-1339 | — | — | 0.4% | Apr 27, 2016 | Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to ... |
| CVE-2015-3572 | — | — | — | Apr 26, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3572. Reason: This candidate is a duplicate of... |
| CVE-2015-3571 | — | — | — | Apr 26, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3571. Reason: This candidate is a duplicate of... |
| CVE-2015-3569 | — | — | — | Apr 26, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3569. Reason: This candidate is a duplicate of... |
| CVE-2015-8852 | — | — | 3.4% | Apr 25, 2016 | Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP h... |
| CVE-2015-5370 | — | — | 19.2% | Apr 25, 2016 | Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC laye... |
| CVE-2015-8823 | HIGH | 8.8 | 6.4% | Apr 22, 2016 | Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and... |
| CVE-2015-4829 | — | — | — | Apr 22, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0638. Reason: This candidate is a reservation ... |
| CVE-2015-6479 | MEDIUM | 4.3 | 1.5% | Apr 21, 2016 | ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows rem... |
| CVE-2015-6360 | — | — | 8.3% | Apr 21, 2016 | The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via... |
| CVE-2015-8842 | — | — | 0.4% | Apr 20, 2016 | tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows... |
| CVE-2015-7802 | — | — | 1.6% | Apr 20, 2016 | gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitializ... |
| CVE-2015-7801 | — | — | 5.4% | Apr 20, 2016 | Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file. |
| CVE-2015-8779 | — | — | 6.0% | Apr 19, 2016 | Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context... |
| CVE-2015-8778 | — | — | 5.5% | Apr 19, 2016 | Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a den... |
| CVE-2015-8776 | — | — | 4.6% | Apr 19, 2016 | The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause ... |
| CVE-2015-7511 | — | — | 0.4% | Apr 19, 2016 | Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it e... |
| CVE-2015-1776 | — | — | 0.3% | Apr 19, 2016 | Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now