2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0232 | — | — | 15.4% | Jan 27, 2015 | The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 a... |
| CVE-2015-0231 | — | — | 42.6% | Jan 27, 2015 | Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.3... |
| CVE-2015-1308 | — | — | 1.4% | Jan 26, 2015 | kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently ... |
| CVE-2015-1307 | — | — | 1.2% | Jan 26, 2015 | plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package. |
| CVE-2015-1179 | — | — | 1.5% | Jan 26, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in data_point_details.shtm in Mango Automation 2.4.0 and earlier all... |
| CVE-2015-1178 | — | — | 1.9% | Jan 26, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to in... |
| CVE-2015-0311 | CRITICAL | 9.8 | 85.8% | Jan 23, 2015 | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window... |
| CVE-2015-0310 | HIGH | 7.8 | 15.2% | Jan 23, 2015 | Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438... |
| CVE-2015-1347 | — | — | 1.4% | Jan 23, 2015 | Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject ... |
| CVE-2015-1200 | — | — | 0.3% | Jan 23, 2015 | Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before chan... |
| CVE-2015-1180 | — | — | 1.5% | Jan 23, 2015 | Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbit... |
| CVE-2015-1176 | — | — | 1.9% | Jan 23, 2015 | Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to i... |
| CVE-2015-1346 | — | — | 1.2% | Jan 22, 2015 | Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow... |
| CVE-2015-1205 | — | — | 1.8% | Jan 22, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service o... |
| CVE-2015-1312 | — | — | 1.3% | Jan 22, 2015 | The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive inform... |
| CVE-2015-1311 | — | — | 2.2% | Jan 22, 2015 | The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified... |
| CVE-2015-1310 | — | — | 1.2% | Jan 22, 2015 | SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute arbitrary ... |
| CVE-2015-1309 | — | — | 2.2% | Jan 22, 2015 | XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and ear... |
| CVE-2015-1175 | — | — | 1.9% | Jan 22, 2015 | Cross-site scripting (XSS) vulnerability in blocklayered-ajax.php in the blocklayered module in PrestaShop 1.6.0.9 and e... |
| CVE-2015-1306 | — | — | 2.4% | Jan 22, 2015 | The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote atta... |
| CVE-2015-0925 | — | — | 52.1% | Jan 22, 2015 | The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via ... |
| CVE-2015-0437 | — | — | 4.0% | Jan 21, 2015 | Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and avail... |
| CVE-2015-0436 | — | — | 1.3% | Jan 21, 2015 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to a... |
| CVE-2015-0435 | — | — | 1.3% | Jan 21, 2015 | Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6... |
| CVE-2015-0434 | — | — | 1.2% | Jan 21, 2015 | Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now