2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1303 | — | — | 1.7% | Oct 12, 2015 | bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow acti... |
| CVE-2015-5659 | — | — | 1.7% | Oct 11, 2015 | SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote ... |
| CVE-2015-5654 | — | — | 2.2% | Oct 11, 2015 | Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web scri... |
| CVE-2015-5648 | — | — | 1.1% | Oct 11, 2015 | SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitra... |
| CVE-2015-4929 | — | — | 1.4% | Oct 11, 2015 | IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote au... |
| CVE-2015-7768 | — | — | 63.2% | Oct 9, 2015 | Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma... |
| CVE-2015-7767 | — | — | 4.7% | Oct 9, 2015 | Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of... |
| CVE-2015-7766 | — | — | 80.6% | Oct 9, 2015 | PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q... |
| CVE-2015-7765 | — | — | 67.3% | Oct 9, 2015 | ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a... |
| CVE-2015-5235 | — | — | 3.0% | Oct 9, 2015 | IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows... |
| CVE-2015-5234 | — | — | 2.1% | Oct 9, 2015 | IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to... |
| CVE-2015-1337 | — | — | 1.7% | Oct 9, 2015 | Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirr... |
| CVE-2015-7761 | — | — | 1.4% | Oct 9, 2015 | Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive... |
| CVE-2015-7760 | — | — | 2.2% | Oct 9, 2015 | libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which ... |
| CVE-2015-5923 | — | — | 0.3% | Oct 9, 2015 | Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically prox... |
| CVE-2015-5922 | — | — | 3.0% | Oct 9, 2015 | Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.1... |
| CVE-2015-5919 | — | — | 0.4% | Oct 9, 2015 | GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption... |
| CVE-2015-5918 | — | — | 0.4% | Oct 9, 2015 | GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption... |
| CVE-2015-5917 | — | — | 2.7% | Oct 9, 2015 | The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to c... |
| CVE-2015-5915 | — | — | 1.5% | Oct 9, 2015 | Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified imp... |
| CVE-2015-5914 | — | — | 0.4% | Oct 9, 2015 | The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI upd... |
| CVE-2015-5913 | — | — | 1.8% | Oct 9, 2015 | Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server vi... |
| CVE-2015-5902 | — | — | 0.4% | Oct 9, 2015 | The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a den... |
| CVE-2015-5901 | — | — | 0.4% | Oct 9, 2015 | The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow lo... |
| CVE-2015-5900 | — | — | 1.6% | Oct 9, 2015 | The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attack... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now