2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1350 | MEDIUM | 5.5 | 0.5% | May 2, 2016 | The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that undersp... |
| CVE-2015-8816 | MEDIUM | 6.8 | 0.5% | Apr 27, 2016 | The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-in... |
| CVE-2015-7515 | MEDIUM | 4.6 | 1.8% | Apr 27, 2016 | The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at... |
| CVE-2015-6479 | MEDIUM | 4.3 | 1.5% | Apr 21, 2016 | ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows rem... |
| CVE-2015-8336 | MEDIUM | 4.3 | 0.6% | Apr 14, 2016 | Huawei FusionCompute with software before V100R005C10SPC700 allows remote authenticated users to obtain sensitive "role ... |
| CVE-2015-8784 | MEDIUM | 6.5 | 4.0% | Apr 13, 2016 | The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds wri... |
| CVE-2015-8553 | MEDIUM | 6.5 | 0.4% | Apr 13, 2016 | Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not e... |
| CVE-2015-8551 | MEDIUM | 6 | 0.5% | Apr 13, 2016 | The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, a... |
| CVE-2015-5158 | MEDIUM | 5.5 | 0.4% | Apr 12, 2016 | Stack-based buffer overflow in hw/scsi/scsi-bus.c in QEMU, when built with SCSI-device emulation support, allows guest O... |
| CVE-2015-7560 | MEDIUM | 6.5 | 12.7% | Mar 13, 2016 | The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x be... |
| CVE-2015-8631 | MEDIUM | 6.5 | 4.6% | Feb 13, 2016 | Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x b... |
| CVE-2015-8629 | MEDIUM | 5.3 | 3.7% | Feb 13, 2016 | The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x... |
| CVE-2015-8785 | MEDIUM | 6.2 | 0.6% | Feb 8, 2016 | The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial... |
| CVE-2015-7513 | MEDIUM | 6.5 | 0.6% | Feb 8, 2016 | arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which ... |
| CVE-2015-7916 | MEDIUM | 6.5 | 0.7% | Feb 6, 2016 | Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote authenticated ... |
| CVE-2015-8783 | MEDIUM | 6.5 | 2.7% | Feb 1, 2016 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image. |
| CVE-2015-8782 | MEDIUM | 6.5 | 2.7% | Feb 1, 2016 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a di... |
| CVE-2015-8781 | MEDIUM | 6.5 | 2.9% | Feb 1, 2016 | tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of sample... |
| CVE-2015-7744 | MEDIUM | 5.9 | 5.0% | Jan 22, 2016 | wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CR... |
| CVE-2015-5299 | MEDIUM | 5.3 | 13.3% | Dec 29, 2015 | The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x b... |
| CVE-2015-5296 | MEDIUM | 5.4 | 7.3% | Dec 29, 2015 | Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but ... |
| CVE-2015-8660 | MEDIUM | 6.7 | 22.4% | Dec 28, 2015 | The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op... |
| CVE-2015-3195 | MEDIUM | 5.3 | 38.7% | Dec 6, 2015 | The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 bef... |
| CVE-2015-4902 | MEDIUM | 5.3 | 13.4% | Oct 22, 2015 | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknow... |
| CVE-2015-6477 | MEDIUM | 6.1 | 12.0% | Oct 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now