2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1914 | — | — | 4.5% | Jul 2, 2015 | IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote a... |
| CVE-2015-0192 | CRITICAL | 9.8 | 4.5% | Jul 2, 2015 | Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR... |
| CVE-2015-5365 | — | — | 1.1% | Jul 2, 2015 | Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web sc... |
| CVE-2015-4238 | — | — | 1.7% | Jul 2, 2015 | The SNMP implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4(7) and 8.6(1.2) allows remote authentica... |
| CVE-2015-4228 | — | — | 0.8% | Jul 2, 2015 | Cisco Digital Content Manager (DCM) 15.0.0 might allow remote ad servers to cause a denial of service (reboot) via malfo... |
| CVE-2015-3443 | — | — | 2.0% | Jul 2, 2015 | Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before... |
| CVE-2015-3157 | — | — | — | Jul 2, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-4233 | — | — | 2.0% | Jul 2, 2015 | SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrar... |
| CVE-2015-5356 | — | — | 1.8% | Jul 1, 2015 | Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers ... |
| CVE-2015-5355 | — | — | 1.9% | Jul 1, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbit... |
| CVE-2015-5354 | — | — | 12.5% | Jul 1, 2015 | Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites ... |
| CVE-2015-5353 | — | — | 7.1% | Jul 1, 2015 | Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo... |
| CVE-2015-4696 | — | — | 6.0% | Jul 1, 2015 | Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafte... |
| CVE-2015-4695 | — | — | 6.6% | Jul 1, 2015 | meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF fil... |
| CVE-2015-4588 | — | — | 9.2% | Jul 1, 2015 | Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of se... |
| CVE-2015-3204 | — | — | 2.6% | Jul 1, 2015 | libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet wit... |
| CVE-2015-3164 | — | — | 0.4% | Jul 1, 2015 | The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which... |
| CVE-2015-2141 | — | — | 2.9% | Jul 1, 2015 | The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key op... |
| CVE-2015-1330 | — | — | 1.4% | Jul 1, 2015 | unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confne... |
| CVE-2015-0848 | — | — | 8.5% | Jul 1, 2015 | Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly ex... |
| CVE-2015-1967 | — | — | 1.7% | Jul 1, 2015 | MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which al... |
| CVE-2015-1951 | — | — | 0.3% | Jul 1, 2015 | IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does no... |
| CVE-2015-1950 | — | — | 0.4% | Jul 1, 2015 | IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interprete... |
| CVE-2015-4226 | — | — | 2.8% | Jun 30, 2015 | The packet-storing feature on Cisco 9900 phones with firmware 9.3(2) does not properly support the RTP protocol, which a... |
| CVE-2015-2966 | — | — | 1.7% | Jun 30, 2015 | Directory traversal vulnerability in the Droidware UK Explorer+ File Manager application before 2.3.3 for Android allows... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now