2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0863 | — | — | 0.7% | Mar 27, 2017 | GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in... |
| CVE-2015-8310 | — | — | 0.8% | Mar 27, 2017 | Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbit... |
| CVE-2015-8309 | — | — | 6.7% | Mar 27, 2017 | Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file... |
| CVE-2015-8678 | — | — | 0.8% | Mar 24, 2017 | The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, ... |
| CVE-2015-8556 | — | — | 13.4% | Mar 24, 2017 | Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. |
| CVE-2015-8687 | — | — | 0.6% | Mar 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manag... |
| CVE-2015-8628 | — | — | 1.4% | Mar 23, 2017 | The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUpl... |
| CVE-2015-8627 | — | — | 1.4% | Mar 23, 2017 | MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize... |
| CVE-2015-8626 | — | — | 1.9% | Mar 23, 2017 | The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x be... |
| CVE-2015-8625 | — | — | 1.8% | Mar 23, 2017 | MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize ... |
| CVE-2015-8624 | — | — | 0.7% | Mar 23, 2017 | The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before ... |
| CVE-2015-8623 | — | — | 0.7% | Mar 23, 2017 | The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not per... |
| CVE-2015-8622 | — | — | 1.5% | Mar 23, 2017 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.... |
| CVE-2015-5729 | — | — | 5.0% | Mar 23, 2017 | The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers gen... |
| CVE-2015-4166 | — | — | 0.7% | Mar 23, 2017 | Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecif... |
| CVE-2015-4078 | — | — | 0.5% | Mar 23, 2017 | Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, w... |
| CVE-2015-2263 | — | — | 0.3% | Mar 23, 2017 | Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global rea... |
| CVE-2015-0855 | — | — | 3.2% | Mar 23, 2017 | The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via s... |
| CVE-2015-8984 | — | — | 2.4% | Mar 20, 2017 | The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to ca... |
| CVE-2015-8983 | — | — | 3.9% | Mar 20, 2017 | Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2... |
| CVE-2015-8954 | — | — | 3.3% | Mar 20, 2017 | The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might a... |
| CVE-2015-1610 | — | — | 1.4% | Mar 20, 2017 | hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC... |
| CVE-2015-3883 | — | — | 0.8% | Mar 17, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or... |
| CVE-2015-3882 | — | — | 1.2% | Mar 17, 2017 | qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], w... |
| CVE-2015-3881 | — | — | 1.5% | Mar 17, 2017 | Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now