2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6526 | — | — | 0.4% | Aug 31, 2015 | The perf_callchain_user_64 function in arch/powerpc/perf/callchain.c in the Linux kernel before 4.0.2 on ppc64 platforms... |
| CVE-2015-6272 | — | — | 1.9% | Aug 31, 2015 | Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remot... |
| CVE-2015-6271 | — | — | 2.0% | Aug 31, 2015 | Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remot... |
| CVE-2015-6270 | — | — | 1.9% | Aug 31, 2015 | Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Pr... |
| CVE-2015-6269 | — | — | 1.9% | Aug 31, 2015 | Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Pr... |
| CVE-2015-4036 | — | — | 0.6% | Aug 31, 2015 | Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow ... |
| CVE-2015-2135 | — | — | 8.9% | Aug 31, 2015 | Unspecified vulnerability in HP Intelligent Provisioning 1.00 through 1.62(a), 2.00, and 2.10 allows remote attackers to... |
| CVE-2015-6754 | — | — | 0.7% | Aug 31, 2015 | Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7... |
| CVE-2015-6753 | — | — | 0.8% | Aug 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit module 7.x-1.x before 7.x-1.2 for Drupal allow rem... |
| CVE-2015-6655 | — | — | 2.0% | Aug 31, 2015 | Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication ... |
| CVE-2015-6752 | — | — | 0.7% | Aug 31, 2015 | Cross-site scripting (XSS) vulnerability in the Search API Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when t... |
| CVE-2015-6751 | — | — | 1.4% | Aug 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow r... |
| CVE-2015-6535 | — | — | 1.3% | Aug 31, 2015 | Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for W... |
| CVE-2015-6750 | — | — | 7.7% | Aug 31, 2015 | Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long ... |
| CVE-2015-6747 | — | — | 1.2% | Aug 31, 2015 | Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attacker... |
| CVE-2015-6746 | — | — | 0.6% | Aug 31, 2015 | Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remo... |
| CVE-2015-6745 | — | — | 0.3% | Aug 31, 2015 | Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to b... |
| CVE-2015-6744 | — | — | 1.1% | Aug 31, 2015 | Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail... |
| CVE-2015-6743 | — | — | 1.1% | Aug 31, 2015 | Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote auth... |
| CVE-2015-6742 | — | — | 1.2% | Aug 31, 2015 | Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote aut... |
| CVE-2015-0943 | — | — | 0.5% | Aug 31, 2015 | Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server... |
| CVE-2015-0942 | — | — | — | Aug 31, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6742, CVE-2015-6743, CVE-2015-6744, CVE-2015-674... |
| CVE-2015-5717 | — | — | 0.7% | Aug 31, 2015 | The Siemens COMPAS Mobile application before 1.6 for Android does not properly verify X.509 certificates from SSL server... |
| CVE-2015-5706 | — | — | 0.4% | Aug 31, 2015 | Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allo... |
| CVE-2015-5697 | — | — | 0.5% | Aug 31, 2015 | The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap da... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now