2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1723 | — | — | 3.3% | Jun 10, 2015 | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S... |
| CVE-2015-1722 | — | — | 3.5% | Jun 10, 2015 | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S... |
| CVE-2015-1721 | — | — | 3.3% | Jun 10, 2015 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and ... |
| CVE-2015-1720 | — | — | 1.9% | Jun 10, 2015 | Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S... |
| CVE-2015-1719 | — | — | 2.6% | Jun 10, 2015 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and ... |
| CVE-2015-1687 | — | — | 13.0% | Jun 10, 2015 | Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (... |
| CVE-2015-4148 | — | — | 18.9% | Jun 9, 2015 | The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not ... |
| CVE-2015-4147 | — | — | 12.3% | Jun 9, 2015 | The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does ... |
| CVE-2015-4026 | — | — | 19.2% | Jun 9, 2015 | The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upo... |
| CVE-2015-4025 | — | — | 20.2% | Jun 9, 2015 | PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character i... |
| CVE-2015-4024 | — | — | 50.1% | Jun 9, 2015 | Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.... |
| CVE-2015-4022 | — | — | 20.3% | Jun 9, 2015 | Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x befor... |
| CVE-2015-4021 | — | — | 20.9% | Jun 9, 2015 | The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does... |
| CVE-2015-3330 | — | — | 14.1% | Jun 9, 2015 | The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x befo... |
| CVE-2015-3329 | — | — | 38.4% | Jun 9, 2015 | Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x befo... |
| CVE-2015-3307 | — | — | 7.7% | Jun 9, 2015 | The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 al... |
| CVE-2015-2783 | — | — | 10.9% | Jun 9, 2015 | ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sens... |
| CVE-2015-4427 | — | — | 1.5% | Jun 9, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (... |
| CVE-2015-4335 | — | — | 9.6% | Jun 9, 2015 | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command. |
| CVE-2015-4109 | — | — | 2.4% | Jun 9, 2015 | Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow... |
| CVE-2015-4080 | — | — | 2.4% | Jun 9, 2015 | The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote... |
| CVE-2015-4010 | — | — | 4.7% | Jun 9, 2015 | Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows rem... |
| CVE-2015-3648 | — | — | 8.1% | Jun 9, 2015 | Directory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote atta... |
| CVE-2015-3624 | — | — | 2.3% | Jun 9, 2015 | Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content ... |
| CVE-2015-3436 | — | — | 0.4% | Jun 9, 2015 | provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local us... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now