2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1673 | — | — | 17.0% | May 13, 2015 | The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and ... |
| CVE-2015-1672 | — | — | 17.5% | May 13, 2015 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of serv... |
| CVE-2015-1671 | HIGH | 7.8 | 54.6% | May 13, 2015 | The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Offi... |
| CVE-2015-1670 | — | — | 16.1% | May 13, 2015 | The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, allo... |
| CVE-2015-1658 | — | — | 15.8% | May 13, 2015 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co... |
| CVE-2015-3981 | — | — | 1.5% | May 12, 2015 | SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 20... |
| CVE-2015-3980 | — | — | 1.4% | May 12, 2015 | SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrar... |
| CVE-2015-3979 | — | — | 2.4% | May 12, 2015 | Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary ... |
| CVE-2015-3978 | — | — | 0.4% | May 12, 2015 | SAP Sybase Unwired Platform Online Data Proxy allows local users to obtain usernames and passwords via the DataVault, ak... |
| CVE-2015-3646 | — | — | 2.9% | May 12, 2015 | OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration optio... |
| CVE-2015-3622 | — | — | 33.1% | May 12, 2015 | The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a den... |
| CVE-2015-3620 | — | — | 2.4% | May 12, 2015 | Cross-site scripting (XSS) vulnerability in the advanced dataset reports page in Fortinet FortiAnalyzer 5.0.0 through 5.... |
| CVE-2015-3451 | — | — | 4.0% | May 12, 2015 | The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote a... |
| CVE-2015-2845 | — | — | 71.7% | May 12, 2015 | The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb... |
| CVE-2015-2844 | — | — | 12.7% | May 12, 2015 | The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arb... |
| CVE-2015-2843 | — | — | 38.1% | May 12, 2015 | Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute ... |
| CVE-2015-2842 | — | — | 13.2% | May 12, 2015 | Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAu... |
| CVE-2015-2829 | — | — | 2.0% | May 12, 2015 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.... |
| CVE-2015-2668 | — | — | 3.2% | May 12, 2015 | ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file. |
| CVE-2015-2234 | — | — | 0.3% | May 12, 2015 | Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permis... |
| CVE-2015-2233 | — | — | 0.4% | May 12, 2015 | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during ... |
| CVE-2015-2222 | — | — | 3.2% | May 12, 2015 | ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file. |
| CVE-2015-2221 | — | — | 3.2% | May 12, 2015 | ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor fil... |
| CVE-2015-2219 | — | — | 4.1% | May 12, 2015 | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allo... |
| CVE-2015-2170 | — | — | 3.2% | May 12, 2015 | The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now