2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-6394The kernel in Cisco NX-OS 5.2(9)N1(1) on Nexus 5000 devices allows local users to cause a denial of service (device cras...
CVE-2015-6391Cisco Unified SIP 3905 phones allow remote attackers to cause a denial of service (resource consumption and functionalit...
CVE-2015-6388Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request fo...
CVE-2015-6387Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote...
CVE-2015-6384The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, whi...
CVE-2015-8078Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote at...
CVE-2015-8077Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote at...
CVE-2015-8076The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows...
CVE-2015-5245CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attacke...
CVE-2015-0860Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x befor...
CVE-2015-0859The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 do...
CVE-2015-6390Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote a...
CVE-2015-6383Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license...
CVE-2015-8024McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manag...
CVE-2015-8395PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly h...
CVE-2015-8394CRITICAL9.8PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a deni...
CVE-2015-8393HIGH7.5pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sen...
CVE-2015-8392PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of s...
CVE-2015-8391CRITICAL9.8The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attac...
CVE-2015-8390CRITICAL9.8PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a deni...
CVE-2015-8389CRITICAL9.8PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a d...
CVE-2015-8388PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parent...
CVE-2015-8387HIGH7.3PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause...
CVE-2015-8386CRITICAL9.8PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows re...
CVE-2015-8385PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, whi...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now