2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7986 | — | — | 6.2% | Oct 27, 2015 | The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni... |
| CVE-2015-5262 | — | — | 19.3% | Oct 27, 2015 | http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.t... |
| CVE-2015-5240 | — | — | 1.0% | Oct 27, 2015 | Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the securit... |
| CVE-2015-5220 | — | — | 3.0% | Oct 27, 2015 | The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Se... |
| CVE-2015-5188 | — | — | 1.1% | Oct 27, 2015 | Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platf... |
| CVE-2015-5178 | — | — | 1.7% | Oct 27, 2015 | The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application S... |
| CVE-2015-3996 | — | — | 0.8% | Oct 27, 2015 | The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework be... |
| CVE-2015-6340 | — | — | 2.0% | Oct 27, 2015 | The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.6073... |
| CVE-2015-5665 | — | — | 0.6% | Oct 27, 2015 | Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijac... |
| CVE-2015-4625 | — | — | 0.4% | Oct 26, 2015 | Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local use... |
| CVE-2015-3256 | — | — | 0.4% | Oct 26, 2015 | PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemo... |
| CVE-2015-3255 | — | — | 0.4% | Oct 26, 2015 | The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before... |
| CVE-2015-3218 | — | — | 0.4% | Oct 26, 2015 | The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) bef... |
| CVE-2015-7674 | — | — | 5.8% | Oct 26, 2015 | Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attac... |
| CVE-2015-7673 | — | — | 5.4% | Oct 26, 2015 | io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to caus... |
| CVE-2015-5286 | — | — | 2.4% | Oct 26, 2015 | OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated ... |
| CVE-2015-5251 | — | — | 2.0% | Oct 26, 2015 | OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated u... |
| CVE-2015-5223 | — | — | 2.5% | Oct 26, 2015 | OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a D... |
| CVE-2015-3280 | — | — | 3.4% | Oct 26, 2015 | OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances f... |
| CVE-2015-7699 | — | — | 4.0% | Oct 26, 2015 | The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authent... |
| CVE-2015-7881 | — | — | 0.9% | Oct 26, 2015 | The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to byp... |
| CVE-2015-7298 | — | — | 0.7% | Oct 26, 2015 | ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSs... |
| CVE-2015-6670 | — | — | 1.4% | Oct 26, 2015 | ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars,... |
| CVE-2015-6500 | — | — | 2.6% | Oct 26, 2015 | Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated use... |
| CVE-2015-5289 | — | — | 5.0% | Oct 26, 2015 | Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 al... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now