2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6388 | — | — | 2.0% | Dec 5, 2015 | Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request fo... |
| CVE-2015-6387 | — | — | 1.4% | Dec 5, 2015 | Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote... |
| CVE-2015-6384 | — | — | 1.5% | Dec 5, 2015 | The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, whi... |
| CVE-2015-8078 | — | — | 2.8% | Dec 3, 2015 | Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote at... |
| CVE-2015-8077 | — | — | 3.3% | Dec 3, 2015 | Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote at... |
| CVE-2015-8076 | — | — | 3.3% | Dec 3, 2015 | The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows... |
| CVE-2015-5245 | — | — | 1.9% | Dec 3, 2015 | CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attacke... |
| CVE-2015-0860 | — | — | 5.0% | Dec 3, 2015 | Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x befor... |
| CVE-2015-0859 | — | — | 2.3% | Dec 3, 2015 | The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 do... |
| CVE-2015-6390 | — | — | 1.4% | Dec 3, 2015 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote a... |
| CVE-2015-6383 | — | — | 0.4% | Dec 3, 2015 | Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license... |
| CVE-2015-8024 | — | — | 3.4% | Dec 2, 2015 | McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manag... |
| CVE-2015-8395 | — | — | 3.5% | Dec 2, 2015 | PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly h... |
| CVE-2015-8392 | — | — | 3.6% | Dec 2, 2015 | PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of s... |
| CVE-2015-8388 | — | — | 6.6% | Dec 2, 2015 | PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parent... |
| CVE-2015-8385 | — | — | 5.6% | Dec 2, 2015 | PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, whi... |
| CVE-2015-8384 | — | — | 3.4% | Dec 2, 2015 | PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back referen... |
| CVE-2015-8382 | — | — | 4.1% | Dec 2, 2015 | The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcde... |
| CVE-2015-8381 | — | — | 5.3% | Dec 2, 2015 | The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles th... |
| CVE-2015-8380 | — | — | 4.4% | Dec 2, 2015 | The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote... |
| CVE-2015-2328 | — | — | 5.2% | Dec 2, 2015 | PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remo... |
| CVE-2015-2327 | — | — | 4.0% | Dec 2, 2015 | PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive bac... |
| CVE-2015-6386 | — | — | 1.7% | Dec 1, 2015 | The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows r... |
| CVE-2015-6385 | — | — | 0.4% | Dec 1, 2015 | The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows... |
| CVE-2015-8214 | — | — | 2.1% | Nov 27, 2015 | A vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now