2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5711 | — | — | 2.3% | Sep 29, 2015 | TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot b... |
| CVE-2015-5442 | — | — | 0.6% | Sep 29, 2015 | Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown v... |
| CVE-2015-0852 | — | — | 2.9% | Sep 29, 2015 | Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of... |
| CVE-2015-6927 | — | — | 0.5% | Sep 28, 2015 | vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml i... |
| CVE-2015-6806 | — | — | 4.1% | Sep 28, 2015 | The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote a... |
| CVE-2015-5957 | — | — | 2.6% | Sep 28, 2015 | Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact ... |
| CVE-2015-5400 | — | — | 16.5% | Sep 28, 2015 | Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows ... |
| CVE-2015-5185 | — | — | 3.4% | Sep 28, 2015 | The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial o... |
| CVE-2015-1781 | — | — | 5.5% | Sep 28, 2015 | Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) bef... |
| CVE-2015-5703 | — | — | 1.7% | Sep 28, 2015 | SQL injection vulnerability in the public key discovery API call in Open-Xchange OX Guard before 2.0.0-rev8 allows remot... |
| CVE-2015-5375 | — | — | 1.9% | Sep 28, 2015 | Cross-site scripting (XSS) vulnerability in unspecified dialogs for printing content in the Front End in Open-Xchange Se... |
| CVE-2015-5372 | — | — | 0.9% | Sep 28, 2015 | The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match ... |
| CVE-2015-5279 | — | — | 1.0% | Sep 28, 2015 | Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS user... |
| CVE-2015-3203 | — | — | 9.4% | Sep 28, 2015 | Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by upload... |
| CVE-2015-7387 | — | — | 80.2% | Sep 28, 2015 | ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions... |
| CVE-2015-7386 | — | — | 1.2% | Sep 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio ... |
| CVE-2015-6928 | — | — | 2.2% | Sep 28, 2015 | classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a passwor... |
| CVE-2015-5082 | — | — | 69.9% | Sep 28, 2015 | Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW... |
| CVE-2015-7383 | — | — | 1.2% | Sep 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-e... |
| CVE-2015-7382 | — | — | 1.5% | Sep 28, 2015 | SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers... |
| CVE-2015-7381 | — | — | 3.2% | Sep 28, 2015 | Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 ... |
| CVE-2015-6463 | — | — | 0.7% | Sep 28, 2015 | CodeWrights HART Comm DTM components, as used with Endress+Hauser FieldCare, allow remote attackers to read arbitrary fi... |
| CVE-2015-6307 | — | — | 0.7% | Sep 28, 2015 | Cisco FirePOWER (formerly Sourcefire) 7000 and 8000 devices with software 5.4.0.1 allow remote attackers to cause a deni... |
| CVE-2015-6280 | — | — | 4.4% | Sep 28, 2015 | The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S... |
| CVE-2015-6279 | — | — | 3.2% | Sep 28, 2015 | The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now