2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2846 | — | — | 3.7% | Apr 13, 2015 | BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link. |
| CVE-2015-2775 | — | — | 8.0% | Apr 13, 2015 | Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers t... |
| CVE-2015-0840 | — | — | 1.8% | Apr 13, 2015 | The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signat... |
| CVE-2015-0677 | — | — | 1.9% | Apr 13, 2015 | The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 befor... |
| CVE-2015-0676 | — | — | 1.1% | Apr 13, 2015 | The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8... |
| CVE-2015-0675 | — | — | 1.0% | Apr 13, 2015 | The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(... |
| CVE-2015-0694 | — | — | 1.6% | Apr 11, 2015 | Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint,... |
| CVE-2015-0692 | — | — | 0.4% | Apr 11, 2015 | Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python... |
| CVE-2015-0678 | — | — | 2.3% | Apr 11, 2015 | The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (... |
| CVE-2015-2247 | — | — | 0.7% | Apr 10, 2015 | Unspecified vulnerability in Boosted Boards skateboards allows physically proximate attackers to modify skateboard movem... |
| CVE-2015-3027 | — | — | 1.3% | Apr 10, 2015 | Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack st... |
| CVE-2015-3008 | — | — | 46.2% | Apr 10, 2015 | Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified ... |
| CVE-2015-3005 | — | — | 1.8% | Apr 10, 2015 | Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before ... |
| CVE-2015-3004 | — | — | 1.8% | Apr 10, 2015 | J-Web in Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D35, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X... |
| CVE-2015-3003 | — | — | 0.4% | Apr 10, 2015 | Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R9, 12... |
| CVE-2015-3002 | — | — | 0.4% | Apr 10, 2015 | Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.... |
| CVE-2015-2806 | — | — | 7.8% | Apr 10, 2015 | Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impa... |
| CVE-2015-2779 | — | — | 2.8% | Apr 10, 2015 | Stack consumption vulnerability in the message splitting functionality in Quassel before 0.12-rc1 allows remote attacker... |
| CVE-2015-2778 | — | — | 2.6% | Apr 10, 2015 | Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to caus... |
| CVE-2015-2295 | — | — | 65.9% | Apr 10, 2015 | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before... |
| CVE-2015-1842 | — | — | 5.2% | Apr 10, 2015 | The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANG... |
| CVE-2015-1415 | — | — | 0.4% | Apr 10, 2015 | The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable p... |
| CVE-2015-1149 | — | — | 1.6% | Apr 10, 2015 | Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denia... |
| CVE-2015-1148 | — | — | 1.5% | Apr 10, 2015 | Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-depen... |
| CVE-2015-1147 | — | — | 1.6% | Apr 10, 2015 | Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances i... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now