2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8709 | — | — | 0.4% | Feb 8, 2016 | kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain priv... |
| CVE-2015-8575 | — | — | 0.5% | Feb 8, 2016 | The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, wh... |
| CVE-2015-8539 | HIGH | 7.8 | 0.4% | Feb 8, 2016 | The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BU... |
| CVE-2015-7566 | — | — | 1.8% | Feb 8, 2016 | The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate a... |
| CVE-2015-7550 | — | — | 0.4% | Feb 8, 2016 | The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphor... |
| CVE-2015-7513 | MEDIUM | 6.5 | 0.6% | Feb 8, 2016 | arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which ... |
| CVE-2015-6398 | — | — | 1.9% | Feb 7, 2016 | Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attac... |
| CVE-2015-7916 | MEDIUM | 6.5 | 0.7% | Feb 6, 2016 | Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote authenticated ... |
| CVE-2015-7915 | — | — | 2.5% | Feb 6, 2016 | Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sen... |
| CVE-2015-7914 | — | — | 2.3% | Feb 6, 2016 | Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge... |
| CVE-2015-6553 | — | — | — | Feb 5, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further in... |
| CVE-2015-2303 | — | — | — | Feb 5, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6406. Reason: This candidate is a reservation ... |
| CVE-2015-2302 | — | — | — | Feb 5, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6405. Reason: This candidate is a reservation ... |
| CVE-2015-8269 | — | — | 2.3% | Feb 4, 2016 | The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by... |
| CVE-2015-8748 | — | — | 2.2% | Feb 3, 2016 | Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacha... |
| CVE-2015-8747 | — | — | 2.9% | Feb 3, 2016 | The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files v... |
| CVE-2015-7546 | HIGH | 7.5 | 1.7% | Feb 3, 2016 | The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keysto... |
| CVE-2015-7539 | — | — | 1.4% | Feb 3, 2016 | The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced... |
| CVE-2015-7538 | — | — | 2.2% | Feb 3, 2016 | Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecifi... |
| CVE-2015-7537 | — | — | 2.4% | Feb 3, 2016 | Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers t... |
| CVE-2015-7536 | — | — | 1.3% | Feb 3, 2016 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated user... |
| CVE-2015-5344 | — | — | 7.1% | Feb 3, 2016 | The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arb... |
| CVE-2015-8783 | MEDIUM | 6.5 | 2.7% | Feb 1, 2016 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image. |
| CVE-2015-8782 | MEDIUM | 6.5 | 2.7% | Feb 1, 2016 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a di... |
| CVE-2015-8781 | MEDIUM | 6.5 | 2.9% | Feb 1, 2016 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of sample... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now