2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3405 | — | — | 5.3% | Aug 9, 2017 | ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy ... |
| CVE-2015-7871 | CRITICAL | 9.8 | 81.8% | Aug 7, 2017 | Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen... |
| CVE-2015-7855 | MEDIUM | 6.5 | 31.1% | Aug 7, 2017 | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause ... |
| CVE-2015-7854 | HIGH | 8.8 | 14.6% | Aug 7, 2017 | Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows rem... |
| CVE-2015-7853 | CRITICAL | 9.8 | 11.8% | Aug 7, 2017 | The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attacker... |
| CVE-2015-7852 | MEDIUM | 5.9 | 12.4% | Aug 7, 2017 | ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) v... |
| CVE-2015-7850 | MEDIUM | 6.5 | 5.0% | Aug 7, 2017 | ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service... |
| CVE-2015-7849 | HIGH | 8.8 | 16.8% | Aug 7, 2017 | Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated us... |
| CVE-2015-7705 | CRITICAL | 9.8 | 12.4% | Aug 7, 2017 | The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified ... |
| CVE-2015-7704 | HIGH | 7.5 | 10.9% | Aug 7, 2017 | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service v... |
| CVE-2015-7702 | MEDIUM | 6.5 | 5.2% | Aug 7, 2017 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a... |
| CVE-2015-7701 | HIGH | 7.5 | 6.5% | Aug 7, 2017 | Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote atta... |
| CVE-2015-7692 | HIGH | 7.5 | 7.3% | Aug 7, 2017 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a... |
| CVE-2015-7691 | HIGH | 7.5 | 7.2% | Aug 7, 2017 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a... |
| CVE-2015-7571 | — | — | 8.4% | Aug 7, 2017 | Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin... |
| CVE-2015-5946 | — | — | 1.7% | Aug 7, 2017 | Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uplo... |
| CVE-2015-5244 | — | — | 2.7% | Aug 7, 2017 | The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass applicati... |
| CVE-2015-8621 | — | — | 0.4% | Aug 7, 2017 | t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally. |
| CVE-2015-7887 | — | — | 1.4% | Aug 7, 2017 | NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups. |
| CVE-2015-7875 | — | — | 1.1% | Aug 7, 2017 | ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "conte... |
| CVE-2015-7561 | — | — | 1.2% | Aug 7, 2017 | Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the... |
| CVE-2015-3839 | — | — | 0.4% | Aug 7, 2017 | The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL poin... |
| CVE-2015-1555 | — | — | 1.4% | Aug 7, 2017 | Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create v... |
| CVE-2015-1378 | — | — | 1.7% | Aug 7, 2017 | cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking t... |
| CVE-2015-9107 | — | — | 4.4% | Aug 4, 2017 | Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now