2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7996 | — | — | 1.0% | Nov 17, 2015 | The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 1... |
| CVE-2015-7995 | — | — | 4.2% | Nov 17, 2015 | The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which a... |
| CVE-2015-7812 | — | — | 0.4% | Nov 17, 2015 | The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to c... |
| CVE-2015-7805 | — | — | 13.4% | Nov 17, 2015 | Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex val... |
| CVE-2015-5602 | — | — | 1.5% | Nov 17, 2015 | sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d... |
| CVE-2015-5311 | — | — | 67.5% | Nov 17, 2015 | PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assert... |
| CVE-2015-5301 | — | — | 1.5% | Nov 17, 2015 | providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.2 and 1.1.x before 1.1.1 does... |
| CVE-2015-5276 | — | — | 2.9% | Nov 17, 2015 | The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle... |
| CVE-2015-5217 | — | — | 1.3% | Nov 17, 2015 | providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check per... |
| CVE-2015-0272 | — | — | 5.1% | Nov 17, 2015 | GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU va... |
| CVE-2015-8219 | — | — | 2.0% | Nov 17, 2015 | The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-val... |
| CVE-2015-8218 | — | — | 1.8% | Nov 17, 2015 | The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, wh... |
| CVE-2015-8217 | — | — | 2.4% | Nov 17, 2015 | The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indica... |
| CVE-2015-8216 | — | — | 2.4% | Nov 17, 2015 | The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks... |
| CVE-2015-8215 | — | — | 3.7% | Nov 16, 2015 | net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU valu... |
| CVE-2015-2924 | — | — | 1.2% | Nov 16, 2015 | The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stac... |
| CVE-2015-7897 | — | — | 7.0% | Nov 16, 2015 | The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge befo... |
| CVE-2015-7816 | — | — | 3.9% | Nov 16, 2015 | The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to co... |
| CVE-2015-7815 | — | — | 3.0% | Nov 16, 2015 | Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to in... |
| CVE-2015-7712 | — | — | 2.1% | Nov 16, 2015 | Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remot... |
| CVE-2015-7872 | — | — | 0.5% | Nov 16, 2015 | The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a de... |
| CVE-2015-7312 | — | — | 0.4% | Nov 16, 2015 | Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the L... |
| CVE-2015-5307 | — | — | 0.6% | Nov 16, 2015 | The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denia... |
| CVE-2015-5257 | — | — | 0.4% | Nov 16, 2015 | drivers/usb/serial/whiteheat.c in the Linux kernel before 4.2.4 allows physically proximate attackers to cause a denial ... |
| CVE-2015-2925 | — | — | 1.2% | Nov 16, 2015 | The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now