2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8384 | — | — | 3.4% | Dec 2, 2015 | PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back referen... |
| CVE-2015-8383 | CRITICAL | 9.8 | 6.1% | Dec 2, 2015 | PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of serv... |
| CVE-2015-8382 | — | — | 4.1% | Dec 2, 2015 | The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcde... |
| CVE-2015-8381 | — | — | 5.3% | Dec 2, 2015 | The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles th... |
| CVE-2015-8380 | — | — | 4.4% | Dec 2, 2015 | The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote... |
| CVE-2015-2328 | — | — | 5.2% | Dec 2, 2015 | PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remo... |
| CVE-2015-2327 | — | — | 4.0% | Dec 2, 2015 | PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive bac... |
| CVE-2015-6386 | — | — | 1.7% | Dec 1, 2015 | The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows r... |
| CVE-2015-6385 | — | — | 0.4% | Dec 1, 2015 | The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows... |
| CVE-2015-8214 | — | — | 2.1% | Nov 27, 2015 | A vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1... |
| CVE-2015-6848 | — | — | 1.9% | Nov 27, 2015 | EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is ... |
| CVE-2015-8365 | — | — | 2.1% | Nov 26, 2015 | The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8... |
| CVE-2015-8364 | — | — | 2.1% | Nov 26, 2015 | Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and ... |
| CVE-2015-8363 | — | — | 2.1% | Nov 26, 2015 | The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.... |
| CVE-2015-6857 | — | — | 3.8% | Nov 26, 2015 | Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows re... |
| CVE-2015-6382 | — | — | 1.7% | Nov 26, 2015 | Cisco ASR 5000 devices with software 16.0(900) allow remote attackers to cause a denial of service (telnetd process rest... |
| CVE-2015-8103 | CRITICAL | 9.8 | 86.8% | Nov 25, 2015 | The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co... |
| CVE-2015-5326 | — | — | 1.8% | Nov 25, 2015 | Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allow... |
| CVE-2015-5325 | — | — | 1.8% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by le... |
| CVE-2015-5324 | — | — | 2.1% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request ... |
| CVE-2015-5323 | — | — | 1.5% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote admin... |
| CVE-2015-5322 | — | — | 3.2% | Nov 25, 2015 | Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directo... |
| CVE-2015-5321 | — | — | 2.1% | Nov 25, 2015 | The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow re... |
| CVE-2015-5320 | — | — | 2.1% | Nov 25, 2015 | Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, whi... |
| CVE-2015-5319 | — | — | 2.3% | Nov 25, 2015 | XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 all... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now