2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2297 | — | — | 1.8% | Oct 6, 2017 | nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application cras... |
| CVE-2015-2158 | — | — | 2.8% | Oct 6, 2017 | Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers t... |
| CVE-2015-1206 | — | — | 0.7% | Oct 6, 2017 | Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged mem... |
| CVE-2015-7980 | — | — | 1.3% | Oct 3, 2017 | Cross-site scripting (XSS) vulnerability in the Compass Rose module 6.x-1.x before 6.x-1.1 for Drupal allows remote atta... |
| CVE-2015-7843 | — | — | 0.9% | Oct 3, 2017 | The management interface on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V... |
| CVE-2015-7841 | — | — | 2.1% | Oct 3, 2017 | The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH228... |
| CVE-2015-7359 | — | — | 0.6% | Oct 3, 2017 | The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.1... |
| CVE-2015-7358 | — | — | 1.2% | Oct 3, 2017 | The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run... |
| CVE-2015-7357 | — | — | 1.9% | Oct 3, 2017 | Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows re... |
| CVE-2015-6971 | — | — | 0.5% | Oct 3, 2017 | Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the... |
| CVE-2015-6576 | — | — | 3.6% | Oct 3, 2017 | Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execut... |
| CVE-2015-3321 | — | — | 0.3% | Oct 3, 2017 | Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalid... |
| CVE-2015-9234 | — | — | 2.0% | Sep 30, 2017 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection vi... |
| CVE-2015-1027 | — | — | 1.2% | Sep 29, 2017 | The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HT... |
| CVE-2015-8249 | — | — | 73.6% | Sep 28, 2017 | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e... |
| CVE-2015-7349 | — | — | 1.3% | Sep 28, 2017 | Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Ci... |
| CVE-2015-7256 | — | — | 0.8% | Sep 28, 2017 | ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A,... |
| CVE-2015-5613 | — | — | 0.9% | Sep 28, 2017 | Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrar... |
| CVE-2015-3643 | — | — | 1.5% | Sep 28, 2017 | usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubu... |
| CVE-2015-3138 | — | — | 2.3% | Sep 28, 2017 | print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process ... |
| CVE-2015-1537 | — | — | 1.8% | Sep 28, 2017 | Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code... |
| CVE-2015-1526 | — | — | 0.5% | Sep 28, 2017 | The media_server component in Android allows remote attackers to cause a denial of service via a crafted application. |
| CVE-2015-1336 | — | — | 1.0% | Sep 28, 2017 | The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t... |
| CVE-2015-7670 | — | — | 3.1% | Sep 26, 2017 | Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordP... |
| CVE-2015-7391 | — | — | 0.8% | Sep 26, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now