2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8621 | — | — | 0.4% | Aug 7, 2017 | t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally. |
| CVE-2015-7887 | — | — | 1.4% | Aug 7, 2017 | NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups. |
| CVE-2015-7875 | — | — | 1.1% | Aug 7, 2017 | ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "conte... |
| CVE-2015-7561 | — | — | 1.2% | Aug 7, 2017 | Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the... |
| CVE-2015-3839 | — | — | 0.4% | Aug 7, 2017 | The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL poin... |
| CVE-2015-1555 | — | — | 1.4% | Aug 7, 2017 | Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create v... |
| CVE-2015-1378 | — | — | 1.7% | Aug 7, 2017 | cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking t... |
| CVE-2015-9107 | — | — | 4.4% | Aug 4, 2017 | Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access ... |
| CVE-2015-8264 | — | — | 2.5% | Aug 2, 2017 | Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and con... |
| CVE-2015-7891 | — | — | 0.7% | Aug 2, 2017 | Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A... |
| CVE-2015-5203 | — | — | 1.9% | Aug 2, 2017 | Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a d... |
| CVE-2015-3642 | — | — | 0.8% | Aug 2, 2017 | The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gatewa... |
| CVE-2015-2690 | — | — | 2.8% | Aug 2, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumadd... |
| CVE-2015-2560 | — | — | 15.6% | Aug 2, 2017 | Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Adminis... |
| CVE-2015-1174 | — | — | 2.9% | Aug 2, 2017 | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote at... |
| CVE-2015-0839 | — | — | 6.3% | Aug 2, 2017 | The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execut... |
| CVE-2015-0194 | — | — | 1.4% | Aug 2, 2017 | XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and... |
| CVE-2015-5059 | — | — | 1.4% | Aug 1, 2017 | The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc... |
| CVE-2015-5191 | — | — | 0.3% | Jul 28, 2017 | VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths... |
| CVE-2015-8013 | — | — | 3.9% | Jul 25, 2017 | s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote a... |
| CVE-2015-6585 | — | — | 2.5% | Jul 25, 2017 | hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by l... |
| CVE-2015-5594 | — | — | 1.9% | Jul 25, 2017 | The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, w... |
| CVE-2015-5221 | — | — | 2.2% | Jul 25, 2017 | Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library... |
| CVE-2015-5187 | — | — | 2.0% | Jul 25, 2017 | Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of ... |
| CVE-2015-4463 | — | — | 1.1% | Jul 25, 2017 | The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-uploa... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now