2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1804 | — | — | 5.0% | Mar 20, 2015 | The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not proper... |
| CVE-2015-1803 | — | — | 4.9% | Mar 20, 2015 | The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not proper... |
| CVE-2015-1802 | — | — | 4.9% | Mar 20, 2015 | The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote a... |
| CVE-2015-0671 | — | — | 1.5% | Mar 20, 2015 | The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attac... |
| CVE-2015-0668 | — | — | 0.9% | Mar 20, 2015 | Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 al... |
| CVE-2015-1787 | — | — | 7.4% | Mar 19, 2015 | The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an... |
| CVE-2015-0293 | — | — | 21.4% | Mar 19, 2015 | The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a al... |
| CVE-2015-0292 | — | — | 44.7% | Mar 19, 2015 | Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenS... |
| CVE-2015-0291 | — | — | 8.1% | Mar 19, 2015 | The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of servi... |
| CVE-2015-0290 | — | — | 7.3% | Mar 19, 2015 | The multi-block feature in the ssl3_write_bytes function in s3_pkt.c in OpenSSL 1.0.2 before 1.0.2a on 64-bit x86 platfo... |
| CVE-2015-0289 | — | — | 8.4% | Mar 19, 2015 | The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a d... |
| CVE-2015-0288 | — | — | 8.5% | Mar 19, 2015 | The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0... |
| CVE-2015-0287 | — | — | 8.4% | Mar 19, 2015 | The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0... |
| CVE-2015-0286 | — | — | 20.8% | Mar 19, 2015 | The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, ... |
| CVE-2015-0285 | — | — | 5.8% | Mar 19, 2015 | The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 before 1.0.2a does not ensure that the PRNG is seeded befor... |
| CVE-2015-0209 | — | — | 16.4% | Mar 19, 2015 | Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 be... |
| CVE-2015-0208 | — | — | 33.7% | Mar 19, 2015 | The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0... |
| CVE-2015-0207 | — | — | 7.3% | Mar 19, 2015 | The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of ... |
| CVE-2015-2352 | — | — | 1.3% | Mar 19, 2015 | The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_ex... |
| CVE-2015-2351 | — | — | 1.9% | Mar 19, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to injec... |
| CVE-2015-2350 | — | — | 1.2% | Mar 19, 2015 | Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack t... |
| CVE-2015-2349 | — | — | 1.9% | Mar 19, 2015 | Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remo... |
| CVE-2015-2281 | — | — | 10.5% | Mar 19, 2015 | Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac... |
| CVE-2015-0896 | — | — | 1.2% | Mar 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary... |
| CVE-2015-0667 | — | — | 1.6% | Mar 18, 2015 | The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attack... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now