2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8264 | — | — | 2.5% | Aug 2, 2017 | Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and con... |
| CVE-2015-7891 | — | — | 0.7% | Aug 2, 2017 | Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A... |
| CVE-2015-5203 | — | — | 1.9% | Aug 2, 2017 | Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a d... |
| CVE-2015-3642 | — | — | 0.8% | Aug 2, 2017 | The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gatewa... |
| CVE-2015-2690 | — | — | 2.8% | Aug 2, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumadd... |
| CVE-2015-2560 | — | — | 15.6% | Aug 2, 2017 | Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Adminis... |
| CVE-2015-1174 | — | — | 2.9% | Aug 2, 2017 | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote at... |
| CVE-2015-0839 | — | — | 6.3% | Aug 2, 2017 | The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execut... |
| CVE-2015-0194 | — | — | 1.4% | Aug 2, 2017 | XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and... |
| CVE-2015-5059 | — | — | 1.4% | Aug 1, 2017 | The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc... |
| CVE-2015-5191 | — | — | 0.3% | Jul 28, 2017 | VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths... |
| CVE-2015-8013 | — | — | 3.9% | Jul 25, 2017 | s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote a... |
| CVE-2015-6585 | — | — | 2.5% | Jul 25, 2017 | hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by l... |
| CVE-2015-5594 | — | — | 1.9% | Jul 25, 2017 | The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, w... |
| CVE-2015-5221 | — | — | 2.2% | Jul 25, 2017 | Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library... |
| CVE-2015-5187 | — | — | 2.0% | Jul 25, 2017 | Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of ... |
| CVE-2015-4463 | — | — | 1.1% | Jul 25, 2017 | The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-uploa... |
| CVE-2015-4462 | — | — | 1.1% | Jul 25, 2017 | Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenti... |
| CVE-2015-4035 | — | — | 1.0% | Jul 25, 2017 | scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons,... |
| CVE-2015-3278 | — | — | 1.5% | Jul 25, 2017 | The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers ... |
| CVE-2015-3243 | — | — | 0.4% | Jul 25, 2017 | rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by read... |
| CVE-2015-3208 | — | — | — | Jul 25, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2015-3171 | MEDIUM | 5.5 | 0.3% | Jul 25, 2017 | sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ ... |
| CVE-2015-3149 | — | — | 0.4% | Jul 25, 2017 | The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitra... |
| CVE-2015-2798 | — | — | 3.3% | Jul 25, 2017 | SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary S... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now