2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8033 | MEDIUM | 5.3 | 0.8% | Aug 14, 2020 | In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account. |
| CVE-2015-8032 | MEDIUM | 5.3 | 0.8% | Aug 14, 2020 | In Textpattern 4.5.7, an unprivileged author can change an article's markup setting. |
| CVE-2015-9549 | MEDIUM | 6.1 | 1.3% | Aug 3, 2020 | A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME ... |
| CVE-2015-7946 | MEDIUM | 4.6 | 0.4% | May 7, 2020 | Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. ... |
| CVE-2015-9546 | MEDIUM | 4.8 | 0.3% | Apr 10, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTT... |
| CVE-2015-7968 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusio... |
| CVE-2015-7344 | MEDIUM | 4.8 | 0.5% | Mar 9, 2020 | HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption]. |
| CVE-2015-7343 | MEDIUM | 4.8 | 0.5% | Mar 9, 2020 | JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter. |
| CVE-2015-5361 | MEDIUM | 6.5 | 0.5% | Feb 28, 2020 | Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open relate... |
| CVE-2015-3006 | MEDIUM | 6.5 | 0.8% | Feb 28, 2020 | On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the de... |
| CVE-2015-2992 | MEDIUM | 6.1 | 7.2% | Feb 27, 2020 | Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability. |
| CVE-2015-2923 | MEDIUM | 6.5 | 1.4% | Feb 20, 2020 | The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to... |
| CVE-2015-0749 | MEDIUM | 6.1 | 0.8% | Feb 19, 2020 | A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cro... |
| CVE-2015-7506 | MEDIUM | 6.5 | 1.1% | Feb 18, 2020 | The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of servic... |
| CVE-2015-5216 | MEDIUM | 6.1 | 1.1% | Feb 17, 2020 | The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python... |
| CVE-2015-5215 | MEDIUM | 6.1 | 1.1% | Feb 17, 2020 | The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 bef... |
| CVE-2015-4715 | MEDIUM | 4.9 | 1.4% | Feb 17, 2020 | The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x ... |
| CVE-2015-7890 | MEDIUM | 5.5 | 1.3% | Feb 12, 2020 | Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung ... |
| CVE-2015-2207 | MEDIUM | 5.4 | 0.9% | Feb 8, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote aut... |
| CVE-2015-1394 | MEDIUM | 5.4 | 2.3% | Feb 8, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote... |
| CVE-2015-3612 | MEDIUM | 5.4 | 0.8% | Feb 4, 2020 | A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspec... |
| CVE-2015-7851 | MEDIUM | 6.5 | 3.9% | Jan 28, 2020 | Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used ... |
| CVE-2015-2249 | MEDIUM | 5.4 | 0.7% | Jan 27, 2020 | Zimbra Collaboration before 8.6.0 patch5 has XSS. |
| CVE-2015-3154 | MEDIUM | 6.1 | 1.0% | Jan 27, 2020 | CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x befo... |
| CVE-2015-1525 | MEDIUM | 5.5 | 0.3% | Jan 24, 2020 | audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy appli... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now