2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3442 | — | — | 3.0% | Sep 7, 2017 | Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API c... |
| CVE-2015-3250 | — | — | 5.1% | Sep 7, 2017 | Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors. |
| CVE-2015-8316 | — | — | 1.7% | Sep 6, 2017 | Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled a... |
| CVE-2015-7294 | HIGH | 7.5 | 2.1% | Sep 6, 2017 | ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username. |
| CVE-2015-7241 | — | — | 12.4% | Sep 6, 2017 | XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. |
| CVE-2015-7225 | — | — | 1.8% | Sep 6, 2017 | Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successful... |
| CVE-2015-6250 | — | — | 1.2% | Sep 6, 2017 | simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically gener... |
| CVE-2015-5959 | — | — | 3.1% | Sep 6, 2017 | Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database passwor... |
| CVE-2015-5948 | — | — | 4.5% | Sep 6, 2017 | Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exi... |
| CVE-2015-5947 | HIGH | 8.1 | 2.7% | Sep 6, 2017 | SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. |
| CVE-2015-5705 | — | — | 3.1% | Sep 6, 2017 | Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a c... |
| CVE-2015-5186 | — | — | 2.8% | Sep 6, 2017 | Audit before 2.4.4 in Linux does not sanitize escape characters in filenames. |
| CVE-2015-3454 | — | — | 3.0% | Sep 6, 2017 | TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to o... |
| CVE-2015-3450 | — | — | 2.1% | Sep 6, 2017 | Heap-based buffer overflow in libaxl 0.6.9 allows attackers to cause a denial of service (memory corruption) or execute ... |
| CVE-2015-3163 | MEDIUM | 4.3 | 1.1% | Sep 6, 2017 | The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote... |
| CVE-2015-3162 | — | — | 0.9% | Sep 6, 2017 | Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remot... |
| CVE-2015-3161 | — | — | 0.8% | Sep 6, 2017 | The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals whe... |
| CVE-2015-3160 | — | — | 1.3% | Sep 6, 2017 | XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to... |
| CVE-2015-2943 | — | — | 0.7% | Sep 6, 2017 | Honda Moto LINC 1.6.1 does not verify SSL certificates. |
| CVE-2015-2210 | — | — | 0.6% | Sep 6, 2017 | The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injectin... |
| CVE-2015-0853 | HIGH | 8.8 | 3.3% | Sep 6, 2017 | svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by usi... |
| CVE-2015-7746 | — | — | 1.6% | Sep 1, 2017 | NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtai... |
| CVE-2015-7711 | — | — | 1.6% | Aug 31, 2017 | Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject ar... |
| CVE-2015-7700 | — | — | 2.2% | Aug 31, 2017 | Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspe... |
| CVE-2015-5958 | HIGH | 8.8 | 27.4% | Aug 31, 2017 | phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now