2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0012 | — | — | 1.6% | Feb 11, 2015 | Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of us... |
| CVE-2015-0010 | — | — | 2.6% | Feb 11, 2015 | The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in M... |
| CVE-2015-0009 | — | — | 8.1% | Feb 11, 2015 | The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W... |
| CVE-2015-0008 | — | — | 28.6% | Feb 11, 2015 | The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind... |
| CVE-2015-0003 | — | — | 4.5% | Feb 11, 2015 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2015-1571 | — | — | 0.9% | Feb 10, 2015 | The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private... |
| CVE-2015-1570 | — | — | 0.5% | Feb 10, 2015 | The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not ... |
| CVE-2015-1569 | — | — | 0.5% | Feb 10, 2015 | Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attacke... |
| CVE-2015-1377 | — | — | 0.4% | Feb 10, 2015 | The Read Mail module in Webmin 1.720 allows local users to read arbitrary files via a symlink attack on an unspecified f... |
| CVE-2015-1169 | — | — | 2.8% | Feb 10, 2015 | Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attack... |
| CVE-2015-1042 | — | — | 2.2% | Feb 10, 2015 | The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular exp... |
| CVE-2015-1548 | — | — | 1.3% | Feb 10, 2015 | mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP requ... |
| CVE-2015-1031 | — | — | 2.4% | Feb 10, 2015 | Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via v... |
| CVE-2015-1559 | — | — | 0.8% | Feb 10, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in administrator.php in Epignosis eFront Open Source Edition ... |
| CVE-2015-1432 | — | — | 1.1% | Feb 10, 2015 | The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the fo... |
| CVE-2015-1431 | — | — | 2.7% | Feb 10, 2015 | Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to injec... |
| CVE-2015-1568 | — | — | 0.6% | Feb 9, 2015 | Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote... |
| CVE-2015-1567 | — | — | 1.1% | Feb 9, 2015 | Cross-site scripting (XSS) vulnerability in the admin page in the GD Infinite Scroll module before 7.x-1.4 for Drupal al... |
| CVE-2015-1566 | — | — | 1.8% | Feb 9, 2015 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary we... |
| CVE-2015-1565 | — | — | 1.1% | Feb 9, 2015 | Cross-site scripting (XSS) vulnerability in the online help in Hitachi Device Manager, Tiered Storage Manager, Replicati... |
| CVE-2015-1564 | — | — | 1.0% | Feb 9, 2015 | Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows re... |
| CVE-2015-0246 | — | — | — | Feb 9, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1493. Reason: This candidate is a reservation ... |
| CVE-2015-1563 | — | — | 0.4% | Feb 9, 2015 | The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial of service by causin... |
| CVE-2015-1562 | — | — | 1.9% | Feb 9, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to inject arbitrary web s... |
| CVE-2015-1558 | — | — | 3.0% | Feb 9, 2015 | Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly r... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now