2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7723 | — | — | 0.6% | Jun 7, 2017 | AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack. |
| CVE-2015-7514 | — | — | 1.6% | Jun 7, 2017 | OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obt... |
| CVE-2015-7326 | — | — | 2.9% | Jun 7, 2017 | XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3. |
| CVE-2015-3830 | — | — | 0.5% | Jun 6, 2017 | The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows r... |
| CVE-2015-1207 | — | — | 0.8% | Jun 6, 2017 | Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a... |
| CVE-2015-9007 | — | — | 0.5% | Jun 6, 2017 | In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exis... |
| CVE-2015-9006 | — | — | 0.4% | Jun 6, 2017 | In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vuln... |
| CVE-2015-9005 | — | — | 0.5% | Jun 6, 2017 | In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerabili... |
| CVE-2015-6531 | — | — | 2.9% | Jun 1, 2017 | Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Pyth... |
| CVE-2015-5473 | — | — | 12.6% | Jun 1, 2017 | Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary... |
| CVE-2015-0936 | CRITICAL | 9.8 | 78.1% | Jun 1, 2017 | Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot... |
| CVE-2015-9059 | — | — | 2.2% | May 28, 2017 | picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line... |
| CVE-2015-0269 | — | — | 1.4% | May 26, 2017 | Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end"... |
| CVE-2015-5211 | CRITICAL | 9.6 | 2.6% | May 25, 2017 | Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versio... |
| CVE-2015-3191 | HIGH | 8.8 | 0.5% | May 25, 2017 | With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo... |
| CVE-2015-3190 | MEDIUM | 6.1 | 0.7% | May 25, 2017 | With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo... |
| CVE-2015-3189 | LOW | 3.7 | 0.8% | May 25, 2017 | With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Clo... |
| CVE-2015-1834 | MEDIUM | 6.5 | 1.7% | May 25, 2017 | A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release ve... |
| CVE-2015-8477 | — | — | 1.5% | May 23, 2017 | Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script ... |
| CVE-2015-8089 | — | — | 0.3% | May 23, 2017 | The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 be... |
| CVE-2015-6817 | — | — | 2.2% | May 23, 2017 | PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user ... |
| CVE-2015-6586 | — | — | 1.3% | May 23, 2017 | The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote att... |
| CVE-2015-5682 | — | — | 1.9% | May 23, 2017 | upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via... |
| CVE-2015-5609 | — | — | 3.2% | May 23, 2017 | Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and d... |
| CVE-2015-5469 | — | — | 10.1% | May 23, 2017 | Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers t... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now