2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8709kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain priv...
CVE-2015-8575The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, wh...
CVE-2015-8539HIGH7.8The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BU...
CVE-2015-7566The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate a...
CVE-2015-7550The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphor...
CVE-2015-7513MEDIUM6.5arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which ...
CVE-2015-6398Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attac...
CVE-2015-7916MEDIUM6.5Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote authenticated ...
CVE-2015-7915Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sen...
CVE-2015-7914Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge...
CVE-2015-6553Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further in...
CVE-2015-2303Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6406. Reason: This candidate is a reservation ...
CVE-2015-2302Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6405. Reason: This candidate is a reservation ...
CVE-2015-8269The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by...
CVE-2015-8748Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacha...
CVE-2015-8747The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files v...
CVE-2015-7546HIGH7.5The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keysto...
CVE-2015-7539The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced...
CVE-2015-7538Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecifi...
CVE-2015-7537Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers t...
CVE-2015-7536Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated user...
CVE-2015-5344The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arb...
CVE-2015-8783MEDIUM6.5tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
CVE-2015-8782MEDIUM6.5tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a di...
CVE-2015-8781MEDIUM6.5tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of sample...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now