2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5625 | — | — | 22.8% | Sep 7, 2015 | Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web scri... |
| CVE-2015-5624 | — | — | 2.3% | Sep 7, 2015 | Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers ... |
| CVE-2015-2989 | — | — | 0.9% | Sep 7, 2015 | Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Twit BBS allows remote attackers to inject arbitrar... |
| CVE-2015-6826 | — | — | 2.5% | Sep 6, 2015 | The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain str... |
| CVE-2015-6825 | — | — | 2.4% | Sep 6, 2015 | The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocat... |
| CVE-2015-6824 | — | — | 2.4% | Sep 6, 2015 | The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data struc... |
| CVE-2015-6823 | — | — | 2.4% | Sep 6, 2015 | The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, whic... |
| CVE-2015-6822 | — | — | 2.4% | Sep 6, 2015 | The destroy_buffers function in libavcodec/sanm.c in FFmpeg before 2.7.2 does not properly maintain height and width val... |
| CVE-2015-6821 | — | — | 2.4% | Sep 6, 2015 | The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2 does not properly maintain the encoding... |
| CVE-2015-6820 | — | — | 2.4% | Sep 6, 2015 | The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax e... |
| CVE-2015-6819 | — | — | 2.4% | Sep 6, 2015 | Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow ... |
| CVE-2015-6818 | — | — | 2.4% | Sep 6, 2015 | The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (ak... |
| CVE-2015-2986 | — | — | 0.9% | Sep 5, 2015 | Cross-site scripting (XSS) vulnerability in rakuto.net hitSuji (rktSNS2) 0.2.2b allows remote attackers to inject arbitr... |
| CVE-2015-2985 | — | — | 0.9% | Sep 5, 2015 | Cross-site scripting (XSS) vulnerability in guide-park.com BBS X102 1.03 allows remote attackers to inject arbitrary web... |
| CVE-2015-6276 | — | — | 1.2% | Sep 5, 2015 | Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insuff... |
| CVE-2015-5986 | — | — | 26.1% | Sep 5, 2015 | openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause ... |
| CVE-2015-5722 | — | — | 33.7% | Sep 5, 2015 | buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial ... |
| CVE-2015-2991 | — | — | 2.7% | Sep 5, 2015 | Buffer overflow in NScripter before 3.00 allows remote attackers to execute arbitrary code via crafted save data. |
| CVE-2015-2990 | — | — | 1.6% | Sep 5, 2015 | Directory traversal vulnerability in zhtml.cgi in NEOJAPAN desknet NEO 2.0R1.0 through 2.5R1.4 allows remote authenticat... |
| CVE-2015-6812 | — | — | 1.4% | Sep 4, 2015 | Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remot... |
| CVE-2015-6811 | — | — | 1.7% | Sep 4, 2015 | SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlie... |
| CVE-2015-6810 | — | — | 1.3% | Sep 4, 2015 | Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, ... |
| CVE-2015-6809 | — | — | 3.6% | Sep 4, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary we... |
| CVE-2015-6808 | — | — | 0.8% | Sep 4, 2015 | Cross-site scripting (XSS) vulnerability in the Spotlight module 7.x-1.x before 7.x-1.5 for Drupal allows remote authent... |
| CVE-2015-6807 | — | — | 0.9% | Sep 4, 2015 | Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 fo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now