2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8482 | — | — | 0.3% | Dec 7, 2015 | Blue Coat Unified Agent before 4.6.2 does not prevent modification of its configuration files when running in local enfo... |
| CVE-2015-8213 | — | — | 4.3% | Dec 7, 2015 | The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1... |
| CVE-2015-8131 | — | — | 0.9% | Dec 7, 2015 | Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remot... |
| CVE-2015-8125 | — | — | 2.5% | Dec 7, 2015 | Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecifie... |
| CVE-2015-8124 | — | — | 2.7% | Dec 7, 2015 | Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, a... |
| CVE-2015-8084 | — | — | 0.9% | Dec 7, 2015 | Huawei USG5500, USG2100, USG2200, and USG5100 unified security gateways with software before V300R001C10SPC600, when "DH... |
| CVE-2015-7348 | — | — | 1.9% | Dec 7, 2015 | Cross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and possibly earlier allows remote attackers to inject arbitr... |
| CVE-2015-5309 | — | — | 3.5% | Dec 7, 2015 | Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (mem... |
| CVE-2015-5006 | — | — | 0.5% | Dec 7, 2015 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, ... |
| CVE-2015-4334 | — | — | 3.3% | Dec 7, 2015 | The default configuration of SGOS in Blue Coat ProxySG before 6.2.16.5, 6.5 before 6.5.7.1, and 6.6 before 6.6.2.1 forwa... |
| CVE-2015-3628 | — | — | 68.5% | Dec 7, 2015 | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.... |
| CVE-2015-3276 | HIGH | 7.5 | 5.3% | Dec 7, 2015 | The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyw... |
| CVE-2015-1344 | — | — | 0.4% | Dec 7, 2015 | The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users... |
| CVE-2015-1342 | — | — | 0.5% | Dec 7, 2015 | LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) q... |
| CVE-2015-5302 | — | — | 2.8% | Dec 7, 2015 | libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attac... |
| CVE-2015-5287 | — | — | 3.3% | Dec 7, 2015 | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm... |
| CVE-2015-5273 | — | — | 0.9% | Dec 7, 2015 | The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows ... |
| CVE-2015-3196 | — | — | 12.8% | Dec 6, 2015 | ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-thread... |
| CVE-2015-3195 | MEDIUM | 5.3 | 38.7% | Dec 6, 2015 | The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 bef... |
| CVE-2015-3194 | HIGH | 7.5 | 44.0% | Dec 6, 2015 | crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial ... |
| CVE-2015-3193 | HIGH | 7.5 | 25.1% | Dec 6, 2015 | The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 pla... |
| CVE-2015-1794 | — | — | 6.2% | Dec 6, 2015 | The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a deni... |
| CVE-2015-8480 | — | — | 1.3% | Dec 6, 2015 | The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.7... |
| CVE-2015-8479 | — | — | 0.6% | Dec 6, 2015 | Use-after-free vulnerability in the AudioOutputDevice::OnDeviceAuthorized function in media/audio/audio_output_device.cc... |
| CVE-2015-8478 | — | — | 0.6% | Dec 6, 2015 | Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now