2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8327 | — | — | 10.2% | Dec 17, 2015 | Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters... |
| CVE-2015-7527 | — | — | 5.2% | Dec 17, 2015 | lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via sh... |
| CVE-2015-7518 | — | — | 1.8% | Dec 17, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attacker... |
| CVE-2015-5277 | — | — | 0.6% | Dec 17, 2015 | The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6... |
| CVE-2015-5204 | — | — | 3.4% | Dec 17, 2015 | CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android befor... |
| CVE-2015-4027 | — | — | 1.2% | Dec 17, 2015 | The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t... |
| CVE-2015-8581 | — | — | — | Dec 16, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0779. Reason: This candidate is a duplicate of C... |
| CVE-2015-8580 | — | — | 3.7% | Dec 16, 2015 | Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2... |
| CVE-2015-8566 | — | — | 8.9% | Dec 16, 2015 | The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspeci... |
| CVE-2015-8565 | — | — | 2.6% | Dec 16, 2015 | Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have ... |
| CVE-2015-8564 | — | — | 2.6% | Dec 16, 2015 | Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via d... |
| CVE-2015-8563 | — | — | 0.8% | Dec 16, 2015 | Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x ... |
| CVE-2015-8562 | — | — | 98.3% | Dec 16, 2015 | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi... |
| CVE-2015-8476 | — | — | 2.0% | Dec 16, 2015 | Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via... |
| CVE-2015-8370 | HIGH | 7.4 | 1.1% | Dec 16, 2015 | Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, ob... |
| CVE-2015-8358 | — | — | 7.0% | Dec 16, 2015 | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t... |
| CVE-2015-8357 | — | — | 8.8% | Dec 16, 2015 | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t... |
| CVE-2015-5304 | — | — | 1.8% | Dec 16, 2015 | Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the ser... |
| CVE-2015-8579 | — | — | 1.5% | Dec 16, 2015 | Kaspersky Total Security 2015 15.0.2.361 allocates memory with Read, Write, Execute (RWX) permissions at predictable add... |
| CVE-2015-8578 | — | — | 1.4% | Dec 16, 2015 | AVG Internet Security 2015 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when pr... |
| CVE-2015-8577 | — | — | 0.4% | Dec 16, 2015 | The Buffer Overflow Protection (BOP) feature in McAfee VirusScan Enterprise before 8.8 Patch 6 allocates memory with Rea... |
| CVE-2015-8461 | — | — | 4.8% | Dec 16, 2015 | Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attack... |
| CVE-2015-8000 | — | — | 54.7% | Dec 16, 2015 | db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of s... |
| CVE-2015-6425 | — | — | 2.4% | Dec 16, 2015 | The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote... |
| CVE-2015-7223 | — | — | 1.8% | Dec 16, 2015 | The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sens... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now