2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0796 | MEDIUM | 6.3 | 0.9% | Mar 2, 2018 | In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could ... |
| CVE-2015-5532 | MEDIUM | 6.1 | 2.1% | Oct 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPr... |
| CVE-2015-1239 | MEDIUM | 6.5 | 1.0% | Oct 18, 2017 | Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, ... |
| CVE-2015-1828 | MEDIUM | 5.9 | 1.5% | Oct 6, 2017 | The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtai... |
| CVE-2015-6748 | MEDIUM | 6.1 | 2.2% | Sep 25, 2017 | Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. |
| CVE-2015-4707 | MEDIUM | 6.1 | 1.8% | Sep 20, 2017 | Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or... |
| CVE-2015-1865 | MEDIUM | 5.1 | 0.2% | Sep 20, 2017 | fts.c in coreutils 8.4 allows local users to delete arbitrary files. |
| CVE-2015-9230 | MEDIUM | 4.8 | 1.6% | Sep 12, 2017 | In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPres... |
| CVE-2015-9229 | MEDIUM | 4.8 | 1.0% | Sep 12, 2017 | In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for ... |
| CVE-2015-8079 | MEDIUM | 5.3 | 1.2% | Sep 7, 2017 | qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db. |
| CVE-2015-3163 | MEDIUM | 4.3 | 1.1% | Sep 6, 2017 | The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote... |
| CVE-2015-7855 | MEDIUM | 6.5 | 31.1% | Aug 7, 2017 | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause ... |
| CVE-2015-7852 | MEDIUM | 5.9 | 12.4% | Aug 7, 2017 | ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) v... |
| CVE-2015-7850 | MEDIUM | 6.5 | 5.0% | Aug 7, 2017 | ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service... |
| CVE-2015-7702 | MEDIUM | 6.5 | 5.2% | Aug 7, 2017 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a... |
| CVE-2015-3171 | MEDIUM | 5.5 | 0.3% | Jul 25, 2017 | sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ ... |
| CVE-2015-9101 | MEDIUM | 5.5 | — | Jun 25, 2017 | The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, ... |
| CVE-2015-8538 | MEDIUM | 6.5 | 1.2% | Jun 7, 2017 | dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV). |
| CVE-2015-3190 | MEDIUM | 6.1 | 0.7% | May 25, 2017 | With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo... |
| CVE-2015-1834 | MEDIUM | 6.5 | 1.7% | May 25, 2017 | A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release ve... |
| CVE-2015-8959 | MEDIUM | 6.5 | 3.4% | Apr 20, 2017 | coders/dds.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (CPU consumption) v... |
| CVE-2015-8345 | MEDIUM | 6.5 | 0.4% | Apr 13, 2017 | The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash an... |
| CVE-2015-8613 | MEDIUM | 6.5 | 0.4% | Apr 11, 2017 | Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulati... |
| CVE-2015-8568 | MEDIUM | 6.5 | 0.5% | Apr 11, 2017 | Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to caus... |
| CVE-2015-8504 | MEDIUM | 6.5 | 3.1% | Apr 11, 2017 | Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic excep... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now