2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3407 | — | — | 2.4% | May 19, 2015 | Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file th... |
| CVE-2015-1846 | — | — | 2.9% | May 19, 2015 | unzoo allows remote attackers to cause a denial of service (infinite loop and resource consumption) via unspecified vect... |
| CVE-2015-1845 | — | — | 5.9% | May 19, 2015 | Buffer overflow in the EntrReadArch function in unzoo might allow remote attackers to execute arbitrary code via unspeci... |
| CVE-2015-0267 | — | — | 0.4% | May 19, 2015 | The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-tools before 2.0.7-19 packages in Red Ha... |
| CVE-2015-8147 | — | — | — | May 19, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8147. Reason: This candidate is a duplicate of... |
| CVE-2015-8146 | — | — | — | May 19, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8146. Reason: This candidate is a duplicate of... |
| CVE-2015-3168 | — | — | — | May 19, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-3164. Reason: This candidate is a reservation ... |
| CVE-2015-0739 | — | — | 2.0% | May 19, 2015 | The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices ... |
| CVE-2015-3631 | — | — | 0.6% | May 18, 2015 | Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an... |
| CVE-2015-3630 | — | — | 0.5% | May 18, 2015 | Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, a... |
| CVE-2015-3629 | HIGH | 7.8 | 0.6% | May 18, 2015 | Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout")... |
| CVE-2015-3627 | — | — | 0.6% | May 18, 2015 | Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the ... |
| CVE-2015-3455 | — | — | 11.4% | May 18, 2015 | Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client... |
| CVE-2015-3306 | — | — | 96.8% | May 18, 2015 | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and ... |
| CVE-2015-2704 | — | — | 2.9% | May 18, 2015 | realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character i... |
| CVE-2015-2667 | — | — | 0.8% | May 18, 2015 | Untrusted search path vulnerability in GNS3 1.2.3 allows local users to gain privileges via a Trojan horse uuid.dll in a... |
| CVE-2015-2346 | — | — | 1.2% | May 18, 2015 | XML external entity (XXE) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote authenticated... |
| CVE-2015-1868 | — | — | 81.8% | May 18, 2015 | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authori... |
| CVE-2015-0278 | — | — | 3.2% | May 18, 2015 | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privilege... |
| CVE-2015-0738 | — | — | 1.5% | May 17, 2015 | Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8... |
| CVE-2015-0735 | — | — | 0.7% | May 17, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attac... |
| CVE-2015-0730 | — | — | 1.5% | May 16, 2015 | The SMB module in Cisco Wide Area Application Services (WAAS) 6.0(1) allows remote attackers to cause a denial of servic... |
| CVE-2015-0729 | — | — | 1.1% | May 16, 2015 | Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE) 5.5(0.1) allows re... |
| CVE-2015-0726 | — | — | 2.8% | May 16, 2015 | The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x befo... |
| CVE-2015-0723 | — | — | 0.8% | May 16, 2015 | The wireless web-authentication subsystem on Cisco Wireless LAN Controller (WLC) devices 7.5.x and 7.6.x before 7.6.120 ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now