2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1870 | — | — | — | Jun 26, 2017 | The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in p... |
| CVE-2015-9101 | MEDIUM | 5.5 | — | Jun 25, 2017 | The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, ... |
| CVE-2015-9100 | — | — | — | Jun 25, 2017 | The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of ... |
| CVE-2015-9099 | — | — | — | Jun 25, 2017 | The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of serv... |
| CVE-2015-9098 | CRITICAL | 9.8 | 14.2% | Jun 22, 2017 | In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Mon... |
| CVE-2015-3254 | — | — | 5.3% | Jun 16, 2017 | The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (... |
| CVE-2015-9056 | — | — | 0.8% | Jun 16, 2017 | Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack. |
| CVE-2015-7732 | — | — | 1.1% | Jun 15, 2017 | The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext. |
| CVE-2015-9033 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer. |
| CVE-2015-9032 | — | — | 0.4% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications. |
| CVE-2015-9031 | — | — | 0.4% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP. |
| CVE-2015-9030 | — | — | 0.8% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication. |
| CVE-2015-9029 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem ... |
| CVE-2015-9028 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routi... |
| CVE-2015-9027 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVi... |
| CVE-2015-9026 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVi... |
| CVE-2015-9025 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application. |
| CVE-2015-9024 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications. |
| CVE-2015-9023 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API. |
| CVE-2015-9022 | — | — | 0.4% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in sev... |
| CVE-2015-9021 | — | — | 0.5% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled. |
| CVE-2015-9020 | — | — | 0.6% | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the un... |
| CVE-2015-4596 | — | — | 0.3% | Jun 13, 2017 | Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges. |
| CVE-2015-3220 | — | — | 3.2% | Jun 13, 2017 | The tlslite library before 0.4.9 for Python allows remote attackers to trigger a denial of service (runtime exception an... |
| CVE-2015-9097 | — | — | 3.4% | Jun 12, 2017 | The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF seq... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now