2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1783 | — | — | 3.5% | Aug 11, 2017 | The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd all... |
| CVE-2015-7894 | — | — | 8.9% | Aug 9, 2017 | The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow... |
| CVE-2015-6816 | — | — | 3.6% | Aug 9, 2017 | ganglia-web before 3.7.1 allows remote attackers to bypass authentication. |
| CVE-2015-6498 | — | — | 2.2% | Aug 9, 2017 | Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as ... |
| CVE-2015-3277 | — | — | 2.5% | Aug 9, 2017 | The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of mu... |
| CVE-2015-2687 | — | — | 0.3% | Aug 9, 2017 | OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes tha... |
| CVE-2015-2674 | — | — | 1.4% | Aug 9, 2017 | Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Pyt... |
| CVE-2015-2313 | — | — | 1.9% | Aug 9, 2017 | Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an ob... |
| CVE-2015-2312 | — | — | 1.9% | Aug 9, 2017 | Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and ... |
| CVE-2015-2311 | — | — | 2.5% | Aug 9, 2017 | Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a d... |
| CVE-2015-1820 | — | — | 4.3% | Aug 9, 2017 | REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtai... |
| CVE-2015-0786 | — | — | 23.6% | Aug 9, 2017 | Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration ... |
| CVE-2015-0785 | — | — | 6.5% | Aug 9, 2017 | com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remot... |
| CVE-2015-0784 | — | — | 6.6% | Aug 9, 2017 | Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged i... |
| CVE-2015-0783 | — | — | 5.0% | Aug 9, 2017 | The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitra... |
| CVE-2015-0782 | — | — | 7.1% | Aug 9, 2017 | SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Managemen... |
| CVE-2015-0781 | — | — | 4.3% | Aug 9, 2017 | Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (... |
| CVE-2015-0780 | — | — | 8.2% | Aug 9, 2017 | SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration... |
| CVE-2015-6941 | — | — | 2.2% | Aug 9, 2017 | win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak passwo... |
| CVE-2015-5619 | — | — | 1.2% | Aug 9, 2017 | Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SS... |
| CVE-2015-4165 | — | — | 4.5% | Aug 9, 2017 | The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files ... |
| CVE-2015-3405 | — | — | 5.3% | Aug 9, 2017 | ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy ... |
| CVE-2015-7571 | — | — | 8.4% | Aug 7, 2017 | Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin... |
| CVE-2015-5946 | — | — | 1.7% | Aug 7, 2017 | Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uplo... |
| CVE-2015-5244 | — | — | 2.7% | Aug 7, 2017 | The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass applicati... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now