2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5536 | — | — | 3.4% | Aug 13, 2015 | Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arb... |
| CVE-2015-5535 | — | — | 2.1% | Aug 13, 2015 | Cross-site scripting (XSS) vulnerability in the qTranslate plugin 2.5.39 and earlier for WordPress allows remote attacke... |
| CVE-2015-5474 | — | — | 3.8% | Aug 13, 2015 | BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a cr... |
| CVE-2015-4666 | — | — | 16.2% | Aug 13, 2015 | Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attack... |
| CVE-2015-4665 | — | — | 3.3% | Aug 13, 2015 | Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers ... |
| CVE-2015-3253 | — | — | 44.3% | Aug 13, 2015 | The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to ex... |
| CVE-2015-2321 | — | — | 4.9% | Aug 13, 2015 | Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack... |
| CVE-2015-5718 | — | — | 1.8% | Aug 12, 2015 | Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0... |
| CVE-2015-5166 | — | — | 0.4% | Aug 12, 2015 | Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which a... |
| CVE-2015-5165 | — | — | 13.3% | Aug 12, 2015 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows... |
| CVE-2015-5154 | — | — | 0.6% | Aug 12, 2015 | Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDRO... |
| CVE-2015-3908 | — | — | 0.9% | Aug 12, 2015 | Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or... |
| CVE-2015-3287 | — | — | — | Aug 12, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6587. Reason: This candidate is a duplicate of... |
| CVE-2015-3286 | — | — | 0.4% | Aug 12, 2015 | Buffer overflow in the Solaris kernel extension in OpenAFS before 1.6.13 allows local users to cause a denial of service... |
| CVE-2015-3285 | — | — | 0.4% | Aug 12, 2015 | The pioctl for the OSD FS command in OpenAFS before 1.6.13 uses the wrong pointer when writing the results of the RPC, w... |
| CVE-2015-3284 | — | — | 0.4% | Aug 12, 2015 | pioctls in OpenAFS 1.6.x before 1.6.13 allows local users to read kernel memory via crafted commands. |
| CVE-2015-3283 | — | — | 2.1% | Aug 12, 2015 | OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors. |
| CVE-2015-3282 | — | — | 1.9% | Aug 12, 2015 | vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the n... |
| CVE-2015-3213 | — | — | 0.5% | Aug 12, 2015 | The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via c... |
| CVE-2015-3187 | — | — | 6.5% | Aug 12, 2015 | The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based ... |
| CVE-2015-3184 | — | — | 10.6% | Aug 12, 2015 | mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not ... |
| CVE-2015-2059 | — | — | 3.1% | Aug 12, 2015 | The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to re... |
| CVE-2015-2058 | — | — | 1.9% | Aug 12, 2015 | c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which a... |
| CVE-2015-1867 | — | — | 3.0% | Aug 12, 2015 | Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges v... |
| CVE-2015-1334 | — | — | 0.4% | Aug 12, 2015 | attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now