2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7549 | — | — | 0.4% | Oct 30, 2017 | The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a d... |
| CVE-2015-3249 | — | — | 5.4% | Oct 30, 2017 | The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of... |
| CVE-2015-0226 | — | — | 5.5% | Oct 30, 2017 | Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting... |
| CVE-2015-0224 | — | — | 15.1% | Oct 30, 2017 | qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted ... |
| CVE-2015-1835 | — | — | 5.9% | Oct 27, 2017 | Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml... |
| CVE-2015-6839 | — | — | 0.4% | Oct 23, 2017 | The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physic... |
| CVE-2015-5533 | — | — | 7.2% | Oct 23, 2017 | SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote ... |
| CVE-2015-5379 | — | — | 1.6% | Oct 23, 2017 | Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 a... |
| CVE-2015-2878 | — | — | 4.2% | Oct 23, 2017 | Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijac... |
| CVE-2015-5699 | — | — | 0.4% | Oct 22, 2017 | The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute a... |
| CVE-2015-5177 | — | — | 6.3% | Oct 22, 2017 | Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers... |
| CVE-2015-6668 | — | — | 10.0% | Oct 19, 2017 | The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the ... |
| CVE-2015-4422 | — | — | 0.6% | Oct 19, 2017 | The TEEOS module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users with root pe... |
| CVE-2015-4421 | — | — | 0.9% | Oct 19, 2017 | The tzdriver module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users to gain p... |
| CVE-2015-6961 | — | — | 1.0% | Oct 18, 2017 | Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary we... |
| CVE-2015-5740 | — | — | 3.7% | Oct 18, 2017 | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remot... |
| CVE-2015-5739 | — | — | 9.4% | Oct 18, 2017 | The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allow... |
| CVE-2015-5376 | — | — | 1.2% | Oct 18, 2017 | SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to... |
| CVE-2015-5227 | — | — | 2.9% | Oct 18, 2017 | The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parame... |
| CVE-2015-7943 | — | — | 1.8% | Oct 18, 2017 | Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x... |
| CVE-2015-5164 | — | — | 4.0% | Oct 18, 2017 | The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users... |
| CVE-2015-3400 | — | — | 1.6% | Oct 18, 2017 | sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to t... |
| CVE-2015-2156 | — | — | 5.4% | Oct 18, 2017 | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play F... |
| CVE-2015-7806 | — | — | 6.0% | Oct 17, 2017 | Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.... |
| CVE-2015-7687 | — | — | 4.1% | Oct 16, 2017 | Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or e... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now