2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2046 | — | — | 1.9% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20. |
| CVE-2015-1876 | — | — | 3.1% | Aug 28, 2017 | Directory traversal vulnerability in ES File Explorer 3.2.4.1. |
| CVE-2015-1445 | — | — | 1.8% | Aug 28, 2017 | HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30. |
| CVE-2015-1443 | — | — | 3.5% | Aug 28, 2017 | The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code. |
| CVE-2015-1430 | — | — | 1.2% | Aug 28, 2017 | Buffer overflow in xymon 4.3.17-1. |
| CVE-2015-1401 | — | — | 2.9% | Aug 28, 2017 | Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3. |
| CVE-2015-1386 | — | — | 2.7% | Aug 28, 2017 | Directory traversal vulnerability in unshield 1.0-1. |
| CVE-2015-1199 | — | — | 2.5% | Aug 28, 2017 | Directory traversal vulnerability in ppmd 10.1-5. |
| CVE-2015-1198 | — | — | 3.3% | Aug 28, 2017 | Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5. |
| CVE-2015-1177 | — | — | 1.5% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2. |
| CVE-2015-0974 | — | — | 0.5% | Aug 28, 2017 | Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying th... |
| CVE-2015-0210 | — | — | 0.9% | Aug 28, 2017 | wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-... |
| CVE-2015-0114 | — | — | 0.4% | Aug 28, 2017 | Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1. |
| CVE-2015-0101 | — | — | 0.7% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, ... |
| CVE-2015-5701 | — | — | 0.4% | Aug 25, 2017 | mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files... |
| CVE-2015-5700 | — | — | 0.4% | Aug 25, 2017 | mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via... |
| CVE-2015-4181 | — | — | 11.6% | Aug 25, 2017 | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbi... |
| CVE-2015-4180 | — | — | 2.9% | Aug 25, 2017 | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbi... |
| CVE-2015-4017 | — | — | 1.0% | Aug 25, 2017 | Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules. |
| CVE-2015-3257 | — | — | 0.9% | Aug 25, 2017 | Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote... |
| CVE-2015-3211 | — | — | 0.4% | Aug 25, 2017 | php-fpm allows local users to write to or create arbitrary files via a symlink attack. |
| CVE-2015-3206 | — | — | 2.3% | Aug 25, 2017 | The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allow... |
| CVE-2015-1395 | — | — | 11.2% | Aug 25, 2017 | Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote atta... |
| CVE-2015-1325 | — | — | 0.9% | Aug 25, 2017 | Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ub... |
| CVE-2015-1324 | — | — | 0.4% | Aug 25, 2017 | Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now