2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3150 | HIGH | 7.1 | 0.4% | Jan 14, 2020 | abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files... |
| CVE-2015-3147 | MEDIUM | 6.5 | 1.1% | Jan 14, 2020 | daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-up... |
| CVE-2015-1869 | HIGH | 7.8 | 0.4% | Jan 14, 2020 | The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demons... |
| CVE-2015-2326 | MEDIUM | 5.5 | 1.6% | Jan 14, 2020 | The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a ... |
| CVE-2015-2325 | HIGH | 7.8 | 1.6% | Jan 14, 2020 | The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a de... |
| CVE-2015-0558 | MEDIUM | 5.3 | 1.2% | Jan 14, 2020 | The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other ro... |
| CVE-2015-8367 | CRITICAL | 9.8 | 5.5% | Jan 14, 2020 | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbi... |
| CVE-2015-8366 | CRITICAL | 9.8 | 4.9% | Jan 14, 2020 | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause me... |
| CVE-2015-5951 | CRITICAL | 9.9 | 2.7% | Jan 6, 2020 | A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to ... |
| CVE-2015-4553 | HIGH | 8.8 | 56.7% | Jan 6, 2020 | A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. |
| CVE-2015-4039 | MEDIUM | 5.4 | 2.8% | Jan 6, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent... |
| CVE-2015-9540 | MEDIUM | 6.1 | 0.7% | Jan 4, 2020 | Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503. |
| CVE-2015-5595 | MEDIUM | 6.5 | 1.5% | Dec 31, 2019 | Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack ... |
| CVE-2015-5593 | MEDIUM | 6.1 | 1.1% | Dec 31, 2019 | The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attacker... |
| CVE-2015-5592 | MEDIUM | 6.1 | 1.3% | Dec 31, 2019 | Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting... |
| CVE-2015-5591 | HIGH | 7.2 | 2.2% | Dec 31, 2019 | SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. |
| CVE-2015-5290 | HIGH | 7.5 | 1.9% | Dec 26, 2019 | A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler. |
| CVE-2015-8313 | MEDIUM | 5.9 | 1.7% | Dec 20, 2019 | GnuTLS incorrectly validates the first byte of padding in CBC modes |
| CVE-2015-7892 | HIGH | 7.8 | 1.4% | Dec 9, 2019 | Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in... |
| CVE-2015-3425 | MEDIUM | 6.1 | 0.9% | Dec 9, 2019 | Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows... |
| CVE-2015-3424 | HIGH | 8.8 | 1.6% | Dec 9, 2019 | SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote a... |
| CVE-2015-1853 | MEDIUM | 6.5 | 1.7% | Dec 9, 2019 | chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows... |
| CVE-2015-0841 | HIGH | 7.5 | 2.2% | Dec 9, 2019 | Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attac... |
| CVE-2015-7542 | MEDIUM | 5.3 | 0.4% | Dec 3, 2019 | A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. |
| CVE-2015-0837 | MEDIUM | 5.9 | 2.0% | Nov 29, 2019 | The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now