2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6662 | — | — | 1.6% | Aug 24, 2015 | XML external entity (XXE) vulnerability in SAP NetWeaver Portal 7.4 allows remote attackers to read arbitrary files and ... |
| CVE-2015-6661 | — | — | 2.8% | Aug 24, 2015 | Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu. |
| CVE-2015-6660 | — | — | 1.3% | Aug 24, 2015 | The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remot... |
| CVE-2015-6659 | — | — | 5.1% | Aug 24, 2015 | SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows rem... |
| CVE-2015-6658 | — | — | 2.5% | Aug 24, 2015 | Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows... |
| CVE-2015-6525 | — | — | 4.8% | Aug 24, 2015 | Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context... |
| CVE-2015-6524 | — | — | 8.5% | Aug 24, 2015 | The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x be... |
| CVE-2015-6496 | — | — | 3.2% | Aug 24, 2015 | conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using... |
| CVE-2015-6251 | — | — | 19.0% | Aug 24, 2015 | Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of se... |
| CVE-2015-5964 | — | — | 4.9% | Aug 24, 2015 | The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x b... |
| CVE-2015-5963 | — | — | 5.2% | Aug 24, 2015 | contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, an... |
| CVE-2015-5222 | — | — | 2.7% | Aug 24, 2015 | Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with b... |
| CVE-2015-5058 | — | — | 1.9% | Aug 24, 2015 | Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and P... |
| CVE-2015-3238 | — | — | 2.7% | Aug 24, 2015 | The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly... |
| CVE-2015-0298 | — | — | 1.8% | Aug 24, 2015 | Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote a... |
| CVE-2015-5566 | — | — | 6.5% | Aug 24, 2015 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu... |
| CVE-2015-6565 | — | — | 2.6% | Aug 24, 2015 | sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial ... |
| CVE-2015-6564 | HIGH | 7 | 0.6% | Aug 24, 2015 | Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-Op... |
| CVE-2015-6563 | MEDIUM | 6.4 | 0.4% | Aug 24, 2015 | The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR... |
| CVE-2015-2908 | — | — | 1.8% | Aug 23, 2015 | Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, d... |
| CVE-2015-2907 | — | — | 2.6% | Aug 23, 2015 | Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, h... |
| CVE-2015-2906 | — | — | 2.6% | Aug 23, 2015 | Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, s... |
| CVE-2015-2905 | — | — | 0.7% | Aug 23, 2015 | Cross-site request forgery (CSRF) vulnerability on Actiontec GT784WN modems with firmware before NCS01-1.0.13 allows rem... |
| CVE-2015-2904 | — | — | 0.9% | Aug 23, 2015 | Actiontec GT784WN modems with firmware before NCS01-1.0.13 have hardcoded credentials, which makes it easier for remote ... |
| CVE-2015-2873 | — | — | 2.7% | Aug 23, 2015 | Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x befo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now