2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-8539HIGH7.8The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BU...
CVE-2015-7546HIGH7.5The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keysto...
CVE-2015-7974HIGH7.7NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating pac...
CVE-2015-6831HIGH7.3Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow ...
CVE-2015-6527HIGH7.3The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to exec...
CVE-2015-8397HIGH8.2The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) b...
CVE-2015-1779HIGH8.6The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption...
CVE-2015-8467HIGH7.5The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x ...
CVE-2015-7540HIGH7.5The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful...
CVE-2015-5252HIGH7.2vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with cert...
CVE-2015-8651HIGH8.8Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and bef...
CVE-2015-8543HIGH7The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validat...
CVE-2015-8370HIGH7.4Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, ob...
CVE-2015-6175HIGH7.8The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Ke...
CVE-2015-3276HIGH7.5The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyw...
CVE-2015-3194HIGH7.5crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial ...
CVE-2015-3193HIGH7.5The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 pla...
CVE-2015-8393HIGH7.5pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sen...
CVE-2015-8387HIGH7.3PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause...
CVE-2015-5317HIGH7.5The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive j...
CVE-2015-6855HIGH7.5hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to c...
CVE-2015-6492HIGH7.5Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to...
CVE-2015-7645HIGH7.8Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535...
CVE-2015-2546HIGH8.2The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win...
CVE-2015-2545HIGH7.8Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a c...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now