2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6848 | — | — | 1.9% | Nov 27, 2015 | EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is ... |
| CVE-2015-8365 | — | — | 2.1% | Nov 26, 2015 | The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8... |
| CVE-2015-8364 | — | — | 2.1% | Nov 26, 2015 | Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and ... |
| CVE-2015-8363 | — | — | 2.1% | Nov 26, 2015 | The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.... |
| CVE-2015-6857 | — | — | 3.8% | Nov 26, 2015 | Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows re... |
| CVE-2015-6382 | — | — | 1.7% | Nov 26, 2015 | Cisco ASR 5000 devices with software 16.0(900) allow remote attackers to cause a denial of service (telnetd process rest... |
| CVE-2015-5326 | — | — | 1.8% | Nov 25, 2015 | Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allow... |
| CVE-2015-5325 | — | — | 1.8% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by le... |
| CVE-2015-5324 | — | — | 2.1% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request ... |
| CVE-2015-5323 | — | — | 1.5% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote admin... |
| CVE-2015-5322 | — | — | 3.2% | Nov 25, 2015 | Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directo... |
| CVE-2015-5321 | — | — | 2.1% | Nov 25, 2015 | The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow re... |
| CVE-2015-5320 | — | — | 2.1% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, whi... |
| CVE-2015-5319 | — | — | 2.3% | Nov 25, 2015 | XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 all... |
| CVE-2015-5318 | — | — | 1.1% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which ma... |
| CVE-2015-5306 | — | — | 1.6% | Nov 25, 2015 | OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote at... |
| CVE-2015-5242 | — | — | 2.2% | Nov 25, 2015 | OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metada... |
| CVE-2015-8342 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2015-8135 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7265. Reason: This candidate is a reservation du... |
| CVE-2015-8134 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2015-8133 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7264. Reason: This candidate is a reservation du... |
| CVE-2015-8132 | — | — | — | Nov 25, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7263. Reason: This candidate is a reservation du... |
| CVE-2015-7288 | — | — | 1.7% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 allow remote attackers to modify the configuration via... |
| CVE-2015-7287 | — | — | 3.2% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different custo... |
| CVE-2015-7286 | — | — | 2.1% | Nov 25, 2015 | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hard... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now