2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1798 | — | — | 2.2% | Apr 8, 2015 | The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MA... |
| CVE-2015-1473 | — | — | 2.5% | Apr 8, 2015 | The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly conside... |
| CVE-2015-1472 | — | — | 4.7% | Apr 8, 2015 | The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly conside... |
| CVE-2015-0799 | — | — | 1.2% | Apr 8, 2015 | The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an i... |
| CVE-2015-0798 | — | — | 2.2% | Apr 8, 2015 | The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly ... |
| CVE-2015-2828 | — | — | 3.3% | Apr 8, 2015 | CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authe... |
| CVE-2015-2827 | — | — | 1.9% | Apr 8, 2015 | Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users... |
| CVE-2015-1773 | — | — | 7.0% | Apr 8, 2015 | Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html in Apache Flex before 4.14.1 allows remote attack... |
| CVE-2015-0905 | — | — | 1.0% | Apr 8, 2015 | Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitra... |
| CVE-2015-0876 | — | — | 1.8% | Apr 7, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the print_language_selectbox function in classes/adminpage.inc.ph... |
| CVE-2015-0690 | — | — | 0.9% | Apr 7, 2015 | Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8... |
| CVE-2015-2824 | — | — | 6.3% | Apr 6, 2015 | Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke... |
| CVE-2015-2167 | — | — | 1.2% | Apr 6, 2015 | Open redirect vulnerability in the 3PI Manager in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 all... |
| CVE-2015-2166 | — | — | 26.2% | Apr 6, 2015 | Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5... |
| CVE-2015-2165 | — | — | 1.8% | Apr 6, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Report Viewer in Ericsson Drutt Mobile Service Delivery Platf... |
| CVE-2015-1843 | — | — | 1.6% | Apr 6, 2015 | The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS conn... |
| CVE-2015-1602 | — | — | 0.4% | Apr 6, 2015 | Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, w... |
| CVE-2015-1601 | — | — | 1.4% | Apr 6, 2015 | Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive ... |
| CVE-2015-0877 | — | — | 2.7% | Apr 6, 2015 | Unrestricted file upload vulnerability in app/lib/mlf.pl in C-BOARD Moyuku before 1.03b3 allows remote attackers to exec... |
| CVE-2015-1893 | — | — | 1.7% | Apr 6, 2015 | The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrar... |
| CVE-2015-1890 | — | — | 1.0% | Apr 6, 2015 | /usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentiall... |
| CVE-2015-0179 | — | — | 1.1% | Apr 6, 2015 | Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users t... |
| CVE-2015-0134 | — | — | 4.8% | Apr 6, 2015 | Buffer overflow in the SSLv2 implementation in IBM Domino 8.5.x before 8.5.1 FP5 IF3, 8.5.2 before FP4 IF3, 8.5.3 before... |
| CVE-2015-0119 | — | — | 2.7% | Apr 6, 2015 | FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary... |
| CVE-2015-0117 | — | — | 3.9% | Apr 6, 2015 | The LDAP Server in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows remote attackers to execute... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now