2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1350MEDIUM5.5The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that undersp...
CVE-2015-8325HIGH7.8The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is...
CVE-2015-8845The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms do...
CVE-2015-8844The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the ...
CVE-2015-8816MEDIUM6.8The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-in...
CVE-2015-8812CRITICAL9.8drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which ...
CVE-2015-7515MEDIUM4.6The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at...
CVE-2015-1339Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to ...
CVE-2015-3572Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3572. Reason: This candidate is a duplicate of...
CVE-2015-3571Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3571. Reason: This candidate is a duplicate of...
CVE-2015-3569Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3569. Reason: This candidate is a duplicate of...
CVE-2015-8852Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP h...
CVE-2015-5370Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC laye...
CVE-2015-8823HIGH8.8Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and...
CVE-2015-4829Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0638. Reason: This candidate is a reservation ...
CVE-2015-6479MEDIUM4.3ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows rem...
CVE-2015-6360The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via...
CVE-2015-8842tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows...
CVE-2015-7802gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitializ...
CVE-2015-7801Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.
CVE-2015-8779Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context...
CVE-2015-8778Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a den...
CVE-2015-8776The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause ...
CVE-2015-7511Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it e...
CVE-2015-1776Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now