2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1331 | — | — | 0.5% | Aug 12, 2015 | lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*. |
| CVE-2015-0851 | — | — | 2.4% | Aug 12, 2015 | XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer ... |
| CVE-2015-5965 | — | — | 2.1% | Aug 11, 2015 | The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, wh... |
| CVE-2015-5523 | — | — | 3.8% | Aug 11, 2015 | The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) vi... |
| CVE-2015-5522 | — | — | 4.7% | Aug 11, 2015 | Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause ... |
| CVE-2015-5369 | — | — | 1.8% | Aug 11, 2015 | Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, PCS6500, and MAG PSC360 8.1 before 8.1r5, 8.0 before 8.... |
| CVE-2015-5176 | — | — | 1.6% | Aug 11, 2015 | The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the secu... |
| CVE-2015-4634 | — | — | 2.2% | Aug 11, 2015 | SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL comman... |
| CVE-2015-3626 | — | — | 1.2% | Aug 11, 2015 | Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS ... |
| CVE-2015-3267 | — | — | 1.2% | Aug 11, 2015 | Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows r... |
| CVE-2015-3246 | — | — | 6.9% | Aug 11, 2015 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod... |
| CVE-2015-3245 | — | — | 5.3% | Aug 11, 2015 | Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t... |
| CVE-2015-3228 | — | — | 3.7% | Aug 11, 2015 | Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote at... |
| CVE-2015-2323 | — | — | 1.5% | Aug 11, 2015 | FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when... |
| CVE-2015-1818 | — | — | 2.2% | Aug 11, 2015 | XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.expo... |
| CVE-2015-1805 | — | — | 1.5% | Aug 8, 2015 | The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consid... |
| CVE-2015-2980 | — | — | 2.0% | Aug 8, 2015 | The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and... |
| CVE-2015-2897 | — | — | 2.3% | Aug 8, 2015 | Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier ... |
| CVE-2015-5962 | — | — | 1.1% | Aug 8, 2015 | Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management i... |
| CVE-2015-5961 | — | — | 0.4% | Aug 8, 2015 | The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web s... |
| CVE-2015-5960 | — | — | 0.3% | Aug 8, 2015 | Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and acc... |
| CVE-2015-4495 | HIGH | 8.8 | 70.2% | Aug 8, 2015 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote... |
| CVE-2015-4494 | — | — | 0.8% | Aug 8, 2015 | Mozilla Firefox OS before 2.2 does not require the wifi-manage privilege for reading a Wi-Fi system message, which allow... |
| CVE-2015-2745 | — | — | 1.4% | Aug 8, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Search app in Gaia in Mozilla Firefox OS before 2.2 allow rem... |
| CVE-2015-2744 | — | — | 0.8% | Aug 8, 2015 | Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS before 2.2 allows remote attack... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now