2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5012 | — | — | 1.6% | Feb 15, 2016 | The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, ... |
| CVE-2015-5010 | — | — | 1.6% | Feb 15, 2016 | IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not h... |
| CVE-2015-4991 | — | — | 0.3% | Feb 15, 2016 | IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 thro... |
| CVE-2015-4957 | — | — | 0.6% | Feb 15, 2016 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows ... |
| CVE-2015-4956 | — | — | 0.9% | Feb 15, 2016 | The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspec... |
| CVE-2015-3197 | — | — | 10.7% | Feb 15, 2016 | ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which mak... |
| CVE-2015-2008 | — | — | 0.8% | Feb 15, 2016 | IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup op... |
| CVE-2015-2005 | — | — | 1.1% | Feb 15, 2016 | IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions,... |
| CVE-2015-8631 | MEDIUM | 6.5 | 4.6% | Feb 13, 2016 | Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x b... |
| CVE-2015-8630 | — | — | 4.3% | Feb 13, 2016 | The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in... |
| CVE-2015-8629 | MEDIUM | 5.3 | 3.7% | Feb 13, 2016 | The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x... |
| CVE-2015-7681 | — | — | — | Feb 10, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Notes: none |
| CVE-2015-7680 | — | — | 2.1% | Feb 10, 2016 | Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the us... |
| CVE-2015-7679 | — | — | 1.4% | Feb 10, 2016 | Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitr... |
| CVE-2015-7678 | — | — | 0.9% | Feb 10, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote ... |
| CVE-2015-7677 | — | — | 3.0% | Feb 10, 2016 | The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileI... |
| CVE-2015-7675 | — | — | 3.1% | Feb 10, 2016 | The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authentic... |
| CVE-2015-8361 | — | — | 2.8% | Feb 8, 2016 | Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, w... |
| CVE-2015-8360 | — | — | 3.0% | Feb 8, 2016 | An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arb... |
| CVE-2015-3252 | — | — | 2.2% | Feb 8, 2016 | Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allow... |
| CVE-2015-3251 | — | — | 2.5% | Feb 8, 2016 | Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information ... |
| CVE-2015-2012 | — | — | 0.4% | Feb 8, 2016 | The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 us... |
| CVE-2015-8787 | CRITICAL | 9.8 | 9.2% | Feb 8, 2016 | The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attack... |
| CVE-2015-8785 | MEDIUM | 6.2 | 0.6% | Feb 8, 2016 | The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial... |
| CVE-2015-8767 | — | — | 0.4% | Feb 8, 2016 | net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a s... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now