2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1427 | CRITICAL | 9.8 | 99.9% | Feb 17, 2015 | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s... |
| CVE-2015-0247 | — | — | 0.9% | Feb 17, 2015 | Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execut... |
| CVE-2015-1613 | — | — | 0.9% | Feb 16, 2015 | RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) ... |
| CVE-2015-1501 | — | — | 7.0% | Feb 16, 2015 | The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (S... |
| CVE-2015-1500 | — | — | 8.2% | Feb 16, 2015 | Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (S... |
| CVE-2015-1499 | — | — | 1.4% | Feb 16, 2015 | The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and... |
| CVE-2015-1498 | — | — | 2.3% | Feb 16, 2015 | Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote att... |
| CVE-2015-1497 | — | — | 75.1% | Feb 16, 2015 | radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu... |
| CVE-2015-1496 | — | — | 0.5% | Feb 16, 2015 | Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerSer... |
| CVE-2015-1495 | — | — | 3.3% | Feb 16, 2015 | Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a cra... |
| CVE-2015-1436 | — | — | 2.6% | Feb 16, 2015 | Cross-site scripting (XSS) vulnerability in the Easing Slider plugin before 2.2.0.7 for WordPress allows remote attacker... |
| CVE-2015-1435 | — | — | 2.4% | Feb 16, 2015 | Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web... |
| CVE-2015-1434 | — | — | 1.8% | Feb 16, 2015 | Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary ... |
| CVE-2015-0268 | — | — | 0.4% | Feb 16, 2015 | The vgic_v2_to_sgi function in arch/arm/vgic-v2.c in Xen 4.5.x, when running on ARM hardware with general interrupt cont... |
| CVE-2015-0260 | — | — | 1.2% | Feb 16, 2015 | RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive inform... |
| CVE-2015-1608 | — | — | 1.3% | Feb 16, 2015 | Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection s... |
| CVE-2015-1474 | — | — | 3.7% | Feb 16, 2015 | Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.... |
| CVE-2015-0609 | — | — | 1.2% | Feb 16, 2015 | Race condition in the Common Classification Engine (CCE) in the Measurement, Aggregation, and Correlation Engine (MACE) ... |
| CVE-2015-1574 | — | — | 1.7% | Feb 15, 2015 | The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent app... |
| CVE-2015-0875 | — | — | 0.4% | Feb 15, 2015 | The Ogaki Kyoritsu Bank Smartphone Passbook application 1.0.0 for Android creates a log file containing input data from ... |
| CVE-2015-0519 | — | — | 0.5% | Feb 14, 2015 | The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 p... |
| CVE-2015-0518 | — | — | 3.7% | Feb 14, 2015 | The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P2... |
| CVE-2015-0517 | — | — | 1.2% | Feb 14, 2015 | The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5... |
| CVE-2015-0931 | — | — | 2.4% | Feb 14, 2015 | Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used,... |
| CVE-2015-0923 | — | — | 22.0% | Feb 14, 2015 | The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now