2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7554 | — | — | 4.2% | Jan 8, 2016 | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory ... |
| CVE-2015-7519 | — | — | 2.4% | Jan 8, 2016 | agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache in... |
| CVE-2015-7362 | — | — | 0.4% | Jan 8, 2016 | Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable ... |
| CVE-2015-7328 | — | — | 0.2% | Jan 8, 2016 | Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permission... |
| CVE-2015-6856 | — | — | 0.5% | Jan 8, 2016 | Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locati... |
| CVE-2015-5259 | — | — | 57.0% | Jan 8, 2016 | Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows r... |
| CVE-2015-5254 | — | — | 37.9% | Jan 8, 2016 | Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remot... |
| CVE-2015-8261 | — | — | 3.5% | Jan 8, 2016 | The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized... |
| CVE-2015-6862 | — | — | 1.4% | Jan 8, 2016 | HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrict... |
| CVE-2015-6434 | — | — | 0.9% | Jan 8, 2016 | Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers... |
| CVE-2015-6433 | — | — | 1.2% | Jan 8, 2016 | SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users ... |
| CVE-2015-6647 | — | — | 0.7% | Jan 6, 2016 | The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to... |
| CVE-2015-6646 | — | — | 0.6% | Jan 6, 2016 | The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of ser... |
| CVE-2015-6645 | — | — | 0.3% | Jan 6, 2016 | SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (cont... |
| CVE-2015-6644 | — | — | 0.9% | Jan 6, 2016 | Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information ... |
| CVE-2015-6643 | — | — | 0.2% | Jan 6, 2016 | Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modif... |
| CVE-2015-6642 | — | — | 0.7% | Jan 6, 2016 | The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, an... |
| CVE-2015-6641 | — | — | 0.4% | Jan 6, 2016 | Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveragin... |
| CVE-2015-6640 | — | — | 0.7% | Jan 6, 2016 | The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not e... |
| CVE-2015-6639 | — | — | 6.8% | Jan 6, 2016 | The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to... |
| CVE-2015-6638 | — | — | 0.5% | Jan 6, 2016 | The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gai... |
| CVE-2015-6637 | — | — | 0.6% | Jan 6, 2016 | The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges... |
| CVE-2015-6636 | — | — | 2.1% | Jan 6, 2016 | mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary co... |
| CVE-2015-5310 | — | — | 1.2% | Jan 6, 2016 | The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when manag... |
| CVE-2015-6861 | — | — | 1.0% | Jan 5, 2016 | HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now