2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4674 | — | — | 1.2% | Aug 7, 2015 | The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieve... |
| CVE-2015-3636 | — | — | 2.5% | Aug 6, 2015 | The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str... |
| CVE-2015-4167 | — | — | 0.4% | Aug 5, 2015 | The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values,... |
| CVE-2015-3439 | — | — | 6.0% | Aug 5, 2015 | Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as... |
| CVE-2015-3438 | — | — | 8.5% | Aug 5, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, a... |
| CVE-2015-3963 | — | — | 3.7% | Aug 4, 2015 | Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x b... |
| CVE-2015-3961 | — | — | 1.3% | Aug 4, 2015 | The web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allows remote authen... |
| CVE-2015-3960 | — | — | 0.9% | Aug 4, 2015 | The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches uses hardcoded RSA private keys ... |
| CVE-2015-3959 | — | — | 0.4% | Aug 4, 2015 | The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console p... |
| CVE-2015-3942 | — | — | 1.5% | Aug 4, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web-server component in MNS before 4.5.6 on Belden GarrettCom... |
| CVE-2015-3940 | — | — | 0.5% | Aug 4, 2015 | Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows loca... |
| CVE-2015-4936 | — | — | 1.2% | Aug 3, 2015 | Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial o... |
| CVE-2015-4935 | — | — | 9.0% | Aug 3, 2015 | Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attac... |
| CVE-2015-4934 | — | — | 9.0% | Aug 3, 2015 | Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attac... |
| CVE-2015-4933 | — | — | 9.0% | Aug 3, 2015 | Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attac... |
| CVE-2015-4932 | — | — | 9.0% | Aug 3, 2015 | Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attac... |
| CVE-2015-4931 | — | — | 9.0% | Aug 3, 2015 | Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attac... |
| CVE-2015-1987 | — | — | 2.1% | Aug 3, 2015 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte s... |
| CVE-2015-1970 | — | — | 0.3% | Aug 3, 2015 | The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which ... |
| CVE-2015-1958 | — | — | 1.5% | Aug 3, 2015 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte s... |
| CVE-2015-1956 | — | — | 1.5% | Aug 3, 2015 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte s... |
| CVE-2015-1955 | — | — | 1.5% | Aug 3, 2015 | IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte se... |
| CVE-2015-5623 | — | — | 8.8% | Aug 3, 2015 | WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to by... |
| CVE-2015-5622 | — | — | 5.6% | Aug 3, 2015 | Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary... |
| CVE-2015-3440 | — | — | 17.9% | Aug 3, 2015 | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to i... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now