2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2015-1350MEDIUM5.5The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that undersp...
CVE-2015-8816MEDIUM6.8The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-in...
CVE-2015-7515MEDIUM4.6The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at...
CVE-2015-6479MEDIUM4.3ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows rem...
CVE-2015-8336MEDIUM4.3Huawei FusionCompute with software before V100R005C10SPC700 allows remote authenticated users to obtain sensitive "role ...
CVE-2015-8784MEDIUM6.5The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds wri...
CVE-2015-8553MEDIUM6.5Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not e...
CVE-2015-8551MEDIUM6The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, a...
CVE-2015-5158MEDIUM5.5Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest O...
CVE-2015-7560MEDIUM6.5The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x be...
CVE-2015-8631MEDIUM6.5Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x b...
CVE-2015-8629MEDIUM5.3The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x...
CVE-2015-8785MEDIUM6.2The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial...
CVE-2015-7513MEDIUM6.5arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which ...
CVE-2015-7916MEDIUM6.5Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote authenticated ...
CVE-2015-8783MEDIUM6.5tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
CVE-2015-8782MEDIUM6.5tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a di...
CVE-2015-8781MEDIUM6.5tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of sample...
CVE-2015-7744MEDIUM5.9wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CR...
CVE-2015-5299MEDIUM5.3The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x b...
CVE-2015-5296MEDIUM5.4Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but ...
CVE-2015-8660MEDIUM6.7The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op...
CVE-2015-3195MEDIUM5.3The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 bef...
CVE-2015-4902MEDIUM5.3Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknow...
CVE-2015-6477MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now