2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5291 | — | — | 3.6% | Nov 2, 2015 | Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.... |
| CVE-2015-5210 | — | — | 4.1% | Nov 2, 2015 | Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sit... |
| CVE-2015-3270 | — | — | 2.7% | Nov 2, 2015 | Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via... |
| CVE-2015-3186 | — | — | 2.3% | Nov 2, 2015 | Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator user... |
| CVE-2015-1775 | — | — | 3.0% | Nov 2, 2015 | Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allo... |
| CVE-2015-6354 | — | — | 1.1% | Oct 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remo... |
| CVE-2015-6353 | — | — | 1.1% | Oct 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.3.1.5 and 5.4.x through ... |
| CVE-2015-6343 | — | — | 2.0% | Oct 31, 2015 | The SIP implementation in Cisco IOS 15.5(3)M on Cisco Unified Border Element (CUBE) devices allows remote attackers to c... |
| CVE-2015-6033 | — | — | 2.4% | Oct 31, 2015 | Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-t... |
| CVE-2015-6032 | — | — | 3.3% | Oct 31, 2015 | Qolsys IQ Panel (aka QOL) before 1.5.1 has hardcoded cryptographic keys, which allows remote attackers to create digital... |
| CVE-2015-5667 | — | — | 2.1% | Oct 31, 2015 | Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is e... |
| CVE-2015-8030 | — | — | 4.1% | Oct 30, 2015 | SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted (1) U3D, (2) LWO, ... |
| CVE-2015-8029 | — | — | 3.3% | Oct 30, 2015 | SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted Filmbox document, ... |
| CVE-2015-8028 | — | — | 3.6% | Oct 30, 2015 | Multiple buffer overflows in SAP 3D Visual Enterprise Viewer (VEV) allow remote attackers to execute arbitrary code via ... |
| CVE-2015-7972 | — | — | 0.4% | Oct 30, 2015 | The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_... |
| CVE-2015-7971 | — | — | 0.4% | Oct 30, 2015 | Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hype... |
| CVE-2015-7970 | — | — | 0.4% | Oct 30, 2015 | The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which a... |
| CVE-2015-7969 | — | — | 0.4% | Oct 30, 2015 | Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to ca... |
| CVE-2015-7835 | — | — | 0.4% | Oct 30, 2015 | The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entrie... |
| CVE-2015-7814 | — | — | 0.3% | Oct 30, 2015 | Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6.x and earlier allows local domains with... |
| CVE-2015-7813 | — | — | 0.4% | Oct 30, 2015 | Xen 4.4.x, 4.5.x, and 4.6.x does not limit the number of printk console messages when reporting unimplemented hypercalls... |
| CVE-2015-6352 | — | — | 1.8% | Oct 30, 2015 | Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempt... |
| CVE-2015-6351 | — | — | 1.7% | Oct 30, 2015 | Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices with software 19.1.0.61559 and 19.2.0 allow remote at... |
| CVE-2015-6350 | — | — | 1.4% | Oct 30, 2015 | SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users t... |
| CVE-2015-6349 | — | — | 1.4% | Oct 30, 2015 | Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Serv... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now