2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1438 | — | — | 0.7% | Jul 25, 2017 | Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary ... |
| CVE-2015-1417 | — | — | 3.3% | Jul 25, 2017 | The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x ... |
| CVE-2015-1332 | — | — | 2.6% | Jul 25, 2017 | The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows... |
| CVE-2015-0904 | — | — | 0.8% | Jul 25, 2017 | The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote att... |
| CVE-2015-0674 | — | — | 0.8% | Jul 25, 2017 | Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote at... |
| CVE-2015-8009 | — | — | 2.5% | Jul 25, 2017 | The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4,... |
| CVE-2015-7543 | — | — | 0.2% | Jul 25, 2017 | aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hi... |
| CVE-2015-2280 | — | — | 17.0% | Jul 25, 2017 | snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709... |
| CVE-2015-2279 | — | — | 17.6% | Jul 25, 2017 | cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows... |
| CVE-2015-1847 | — | — | 2.1% | Jul 25, 2017 | Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attacker... |
| CVE-2015-7703 | HIGH | 7.5 | 3.9% | Jul 24, 2017 | The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configur... |
| CVE-2015-5300 | — | — | 9.0% | Jul 21, 2017 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greate... |
| CVE-2015-5219 | HIGH | 7.5 | 5.9% | Jul 21, 2017 | The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value... |
| CVE-2015-5195 | — | — | 7.5% | Jul 21, 2017 | ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault)... |
| CVE-2015-5194 | — | — | 5.6% | Jul 21, 2017 | The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial... |
| CVE-2015-4639 | — | — | 0.6% | Jul 21, 2017 | Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.... |
| CVE-2015-3932 | — | — | 2.1% | Jul 21, 2017 | Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed d... |
| CVE-2015-3931 | — | — | 2.1% | Jul 21, 2017 | Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed... |
| CVE-2015-3886 | — | — | 1.7% | Jul 21, 2017 | libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified... |
| CVE-2015-3640 | — | — | 1.2% | Jul 21, 2017 | phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote aut... |
| CVE-2015-3639 | — | — | 2.0% | Jul 21, 2017 | phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to exec... |
| CVE-2015-3638 | — | — | 2.1% | Jul 21, 2017 | phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary ... |
| CVE-2015-3421 | — | — | 1.3% | Jul 21, 2017 | The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables... |
| CVE-2015-3198 | — | — | 1.8% | Jul 21, 2017 | The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the ... |
| CVE-2015-3170 | — | — | 0.3% | Jul 21, 2017 | selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH logi... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now