2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2684 | — | — | 1.9% | Mar 31, 2015 | Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via... |
| CVE-2015-0838 | — | — | 3.4% | Mar 31, 2015 | Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote att... |
| CVE-2015-2109 | — | — | 4.1% | Mar 31, 2015 | Unspecified vulnerability in HP Operations Orchestration 10.x allows remote attackers to bypass authentication, and obta... |
| CVE-2015-2108 | — | — | 1.9% | Mar 31, 2015 | Unspecified vulnerability in Powershell Operations in HP Operations Orchestration 9.x and 10.x allows remote authenticat... |
| CVE-2015-2106 | — | — | 3.6% | Mar 31, 2015 | Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 all... |
| CVE-2015-0901 | — | — | 2.0% | Mar 31, 2015 | Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attacke... |
| CVE-2015-0900 | — | — | 1.2% | Mar 31, 2015 | Cross-site scripting (XSS) vulnerability in schedule.cgi in Nishishi Factory Fumy Teacher's Schedule Board 1.10 through ... |
| CVE-2015-0985 | — | — | 0.6% | Mar 31, 2015 | Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hij... |
| CVE-2015-0984 | — | — | 5.7% | Mar 31, 2015 | Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C... |
| CVE-2015-2792 | — | — | 3.8% | Mar 30, 2015 | The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote a... |
| CVE-2015-2791 | — | — | 13.4% | Mar 30, 2015 | The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts... |
| CVE-2015-2790 | — | — | 23.1% | Mar 30, 2015 | Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c... |
| CVE-2015-2789 | — | — | 3.2% | Mar 30, 2015 | Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.... |
| CVE-2015-2172 | — | — | 2.9% | Mar 30, 2015 | DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows... |
| CVE-2015-2171 | — | — | 2.5% | Mar 30, 2015 | Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and ex... |
| CVE-2015-1827 | — | — | 2.7% | Mar 30, 2015 | The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when p... |
| CVE-2015-1815 | — | — | 16.4% | Mar 30, 2015 | The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to ex... |
| CVE-2015-1609 | — | — | 2.8% | Mar 30, 2015 | MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 st... |
| CVE-2015-0283 | — | — | 3.1% | Mar 30, 2015 | The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remo... |
| CVE-2015-2787 | — | — | 12.0% | Mar 30, 2015 | Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.3... |
| CVE-2015-2348 | — | — | 8.7% | Mar 30, 2015 | The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5... |
| CVE-2015-2331 | — | — | 27.9% | Mar 30, 2015 | Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extensio... |
| CVE-2015-2305 | — | — | 8.4% | Mar 30, 2015 | Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-... |
| CVE-2015-2301 | — | — | 14.4% | Mar 30, 2015 | Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before ... |
| CVE-2015-1353 | — | — | — | Mar 30, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now