2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7541 | — | — | 3.5% | Jan 8, 2016 | The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby ... |
| CVE-2015-7512 | CRITICAL | 9 | 7.7% | Jan 8, 2016 | Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remot... |
| CVE-2015-8765 | — | — | 2.7% | Jan 8, 2016 | Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.... |
| CVE-2015-8557 | — | — | 6.7% | Jan 8, 2016 | The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers... |
| CVE-2015-4694 | — | — | 15.6% | Jan 8, 2016 | Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote... |
| CVE-2015-8761 | — | — | 1.5% | Jan 8, 2016 | The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrat... |
| CVE-2015-8760 | — | — | 1.4% | Jan 8, 2016 | The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains... |
| CVE-2015-8759 | — | — | 0.6% | Jan 8, 2016 | Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allo... |
| CVE-2015-8758 | — | — | 1.1% | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and ... |
| CVE-2015-8757 | — | — | 1.4% | Jan 8, 2016 | Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allo... |
| CVE-2015-8756 | — | — | 0.8% | Jan 8, 2016 | Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in T... |
| CVE-2015-8755 | — | — | 1.1% | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7... |
| CVE-2015-8754 | — | — | 1.3% | Jan 8, 2016 | The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and ... |
| CVE-2015-8753 | — | — | 2.1% | Jan 8, 2016 | SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a craft... |
| CVE-2015-8668 | CRITICAL | 9.8 | 13.7% | Jan 8, 2016 | Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier ... |
| CVE-2015-8615 | — | — | 1.2% | Jan 8, 2016 | The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages ... |
| CVE-2015-8612 | — | — | 6.3% | Jan 8, 2016 | The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users... |
| CVE-2015-8597 | — | — | 1.9% | Jan 8, 2016 | Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might ... |
| CVE-2015-8547 | — | — | 2.8% | Jan 8, 2016 | The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to ... |
| CVE-2015-8481 | — | — | 1.3% | Jan 8, 2016 | Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong ima... |
| CVE-2015-8303 | — | — | 0.2% | Jan 8, 2016 | Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closi... |
| CVE-2015-8226 | — | — | 0.7% | Jan 8, 2016 | The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL0... |
| CVE-2015-8225 | — | — | 0.7% | Jan 8, 2016 | The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL0... |
| CVE-2015-7758 | — | — | 0.4% | Jan 8, 2016 | Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the na... |
| CVE-2015-7754 | — | — | 3.9% | Jan 8, 2016 | Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of s... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now