2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6373 | — | — | 0.6% | Nov 18, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9... |
| CVE-2015-6372 | — | — | 1.0% | Nov 18, 2015 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating S... |
| CVE-2015-4852 | CRITICAL | 9.8 | 96.0% | Nov 18, 2015 | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers ... |
| CVE-2015-6847 | — | — | 0.5% | Nov 18, 2015 | The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log... |
| CVE-2015-6357 | — | — | 2.6% | Nov 18, 2015 | The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certific... |
| CVE-2015-6330 | — | — | 0.6% | Nov 18, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote at... |
| CVE-2015-8233 | — | — | 1.3% | Nov 17, 2015 | Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal ... |
| CVE-2015-8232 | — | — | 1.1% | Nov 17, 2015 | The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstan... |
| CVE-2015-8222 | — | — | 0.4% | Nov 17, 2015 | The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions f... |
| CVE-2015-8221 | — | — | 4.0% | Nov 17, 2015 | Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAM... |
| CVE-2015-8220 | — | — | 4.8% | Nov 17, 2015 | Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFi... |
| CVE-2015-7998 | — | — | 1.0% | Nov 17, 2015 | The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build ... |
| CVE-2015-7997 | — | — | 1.0% | Nov 17, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller... |
| CVE-2015-7996 | — | — | 1.0% | Nov 17, 2015 | The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 1... |
| CVE-2015-7995 | — | — | 4.2% | Nov 17, 2015 | The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which a... |
| CVE-2015-7812 | — | — | 0.4% | Nov 17, 2015 | The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to c... |
| CVE-2015-7805 | — | — | 13.4% | Nov 17, 2015 | Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex val... |
| CVE-2015-5602 | — | — | 1.5% | Nov 17, 2015 | sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d... |
| CVE-2015-5311 | — | — | 67.5% | Nov 17, 2015 | PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assert... |
| CVE-2015-5301 | — | — | 1.5% | Nov 17, 2015 | providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.2 and 1.1.x before 1.1.1 does... |
| CVE-2015-5276 | — | — | 2.9% | Nov 17, 2015 | The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle... |
| CVE-2015-5217 | — | — | 1.3% | Nov 17, 2015 | providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check per... |
| CVE-2015-0272 | — | — | 5.1% | Nov 17, 2015 | GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU va... |
| CVE-2015-8219 | — | — | 2.0% | Nov 17, 2015 | The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-val... |
| CVE-2015-8218 | — | — | 1.8% | Nov 17, 2015 | The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, wh... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now