2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6027 | MEDIUM | 6.1 | 0.8% | Apr 10, 2017 | Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP. |
| CVE-2015-8985 | MEDIUM | 5.9 | 3.0% | Mar 20, 2017 | The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a deni... |
| CVE-2015-7313 | MEDIUM | 5.5 | 1.5% | Mar 17, 2017 | LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted t... |
| CVE-2015-4645 | MEDIUM | 5.5 | 3.2% | Mar 17, 2017 | Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers... |
| CVE-2015-8896 | MEDIUM | 6.5 | 2.9% | Mar 15, 2017 | Integer truncation issue in coders/pict.c in ImageMagick before 7.0.5-0 allows remote attackers to cause a denial of ser... |
| CVE-2015-6671 | MEDIUM | 5.9 | 0.9% | Mar 13, 2017 | Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it eas... |
| CVE-2015-8903 | MEDIUM | 6.5 | 2.0% | Feb 27, 2017 | The ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a ... |
| CVE-2015-8902 | MEDIUM | 6.5 | 2.0% | Feb 27, 2017 | The ReadBlobByte function in coders/pdb.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a deni... |
| CVE-2015-8901 | MEDIUM | 6.5 | 2.0% | Feb 27, 2017 | ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted M... |
| CVE-2015-8900 | MEDIUM | 5.5 | 1.7% | Feb 27, 2017 | The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of servic... |
| CVE-2015-4056 | MEDIUM | 6.7 | 0.3% | Feb 21, 2017 | The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which mak... |
| CVE-2015-8750 | MEDIUM | 6.5 | 1.9% | Feb 13, 2017 | libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) ... |
| CVE-2015-5013 | MEDIUM | 5.5 | 0.3% | Feb 8, 2017 | The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which... |
| CVE-2015-7977 | MEDIUM | 5.9 | 6.3% | Jan 30, 2017 | ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer de... |
| CVE-2015-7973 | MEDIUM | 6.5 | 3.3% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to con... |
| CVE-2015-8861 | MEDIUM | 6.1 | 3.0% | Jan 23, 2017 | The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by... |
| CVE-2015-8859 | MEDIUM | 5.3 | 4.7% | Jan 23, 2017 | The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors. |
| CVE-2015-8856 | MEDIUM | 6.1 | 2.5% | Jan 23, 2017 | Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to ... |
| CVE-2015-8818 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO r... |
| CVE-2015-8745 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It ... |
| CVE-2015-8744 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It ... |
| CVE-2015-8701 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happen... |
| CVE-2015-8558 | MEDIUM | 5.5 | 0.5% | May 23, 2016 | The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of ser... |
| CVE-2015-3152 | MEDIUM | 5.9 | 7.1% | May 16, 2016 | Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the... |
| CVE-2015-8839 | MEDIUM | 5.1 | 0.4% | May 2, 2016 | Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now