2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2688 | HIGH | 7.5 | 2.2% | Jan 24, 2020 | buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffe... |
| CVE-2015-1530 | HIGH | 7.8 | 0.4% | Jan 24, 2020 | media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_serve... |
| CVE-2015-4041 | HIGH | 7.8 | 0.5% | Jan 24, 2020 | The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculati... |
| CVE-2015-5333 | HIGH | 7.5 | 2.0% | Jan 23, 2020 | Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (m... |
| CVE-2015-1811 | HIGH | 7.5 | 1.4% | Jan 15, 2020 | XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers... |
| CVE-2015-1809 | HIGH | 7.5 | 1.4% | Jan 15, 2020 | XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers... |
| CVE-2015-6497 | HIGH | 8.8 | 7.4% | Jan 15, 2020 | The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.... |
| CVE-2015-5230 | HIGH | 7.5 | 9.0% | Jan 15, 2020 | The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote atta... |
| CVE-2015-5466 | HIGH | 7.8 | 1.1% | Jan 15, 2020 | Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.10... |
| CVE-2015-8549 | HIGH | 7.1 | 1.4% | Jan 15, 2020 | XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or re... |
| CVE-2015-7556 | HIGH | 7.8 | 1.3% | Jan 15, 2020 | DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program. |
| CVE-2015-3159 | HIGH | 7.8 | 0.4% | Jan 14, 2020 | The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly ha... |
| CVE-2015-3151 | HIGH | 7.8 | 0.6% | Jan 14, 2020 | Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write ... |
| CVE-2015-3150 | HIGH | 7.1 | 0.4% | Jan 14, 2020 | abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files... |
| CVE-2015-1869 | HIGH | 7.8 | 0.4% | Jan 14, 2020 | The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demons... |
| CVE-2015-2325 | HIGH | 7.8 | 1.6% | Jan 14, 2020 | The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a de... |
| CVE-2015-4553 | HIGH | 8.8 | 56.7% | Jan 6, 2020 | A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. |
| CVE-2015-5591 | HIGH | 7.2 | 2.2% | Dec 31, 2019 | SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. |
| CVE-2015-5290 | HIGH | 7.5 | 1.9% | Dec 26, 2019 | A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler. |
| CVE-2015-7892 | HIGH | 7.8 | 1.4% | Dec 9, 2019 | Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in... |
| CVE-2015-3424 | HIGH | 8.8 | 1.6% | Dec 9, 2019 | SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote a... |
| CVE-2015-0841 | HIGH | 7.5 | 2.2% | Dec 9, 2019 | Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attac... |
| CVE-2015-3406 | HIGH | 7.5 | 2.3% | Nov 29, 2019 | The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SI... |
| CVE-2015-7831 | HIGH | 8.8 | 1.1% | Nov 26, 2019 | In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used. |
| CVE-2015-6495 | HIGH | 7.5 | 1.1% | Nov 26, 2019 | There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now