2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4462 | — | — | 1.1% | Jul 25, 2017 | Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenti... |
| CVE-2015-4035 | — | — | 1.0% | Jul 25, 2017 | scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons,... |
| CVE-2015-3278 | — | — | 1.5% | Jul 25, 2017 | The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers ... |
| CVE-2015-3243 | — | — | 0.4% | Jul 25, 2017 | rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by read... |
| CVE-2015-3208 | — | — | — | Jul 25, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2015-3149 | — | — | 0.4% | Jul 25, 2017 | The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitra... |
| CVE-2015-2798 | — | — | 3.3% | Jul 25, 2017 | SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary S... |
| CVE-2015-1438 | — | — | 0.7% | Jul 25, 2017 | Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary ... |
| CVE-2015-1417 | — | — | 3.3% | Jul 25, 2017 | The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x ... |
| CVE-2015-1332 | — | — | 2.6% | Jul 25, 2017 | The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows... |
| CVE-2015-0904 | — | — | 0.8% | Jul 25, 2017 | The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote att... |
| CVE-2015-0674 | — | — | 0.8% | Jul 25, 2017 | Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote at... |
| CVE-2015-8009 | — | — | 2.5% | Jul 25, 2017 | The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4,... |
| CVE-2015-7543 | — | — | 0.2% | Jul 25, 2017 | aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hi... |
| CVE-2015-2280 | — | — | 17.0% | Jul 25, 2017 | snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709... |
| CVE-2015-2279 | — | — | 17.6% | Jul 25, 2017 | cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows... |
| CVE-2015-1847 | — | — | 2.1% | Jul 25, 2017 | Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attacker... |
| CVE-2015-5300 | — | — | 9.0% | Jul 21, 2017 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greate... |
| CVE-2015-5195 | — | — | 7.5% | Jul 21, 2017 | ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault)... |
| CVE-2015-5194 | — | — | 5.6% | Jul 21, 2017 | The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial... |
| CVE-2015-4639 | — | — | 0.6% | Jul 21, 2017 | Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.... |
| CVE-2015-3932 | — | — | 2.1% | Jul 21, 2017 | Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed d... |
| CVE-2015-3931 | — | — | 2.1% | Jul 21, 2017 | Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed... |
| CVE-2015-3886 | — | — | 1.7% | Jul 21, 2017 | libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified... |
| CVE-2015-3640 | — | — | 1.2% | Jul 21, 2017 | phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote aut... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now