2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8140 | — | — | 4.6% | Jan 30, 2017 | The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sniffing the network. |
| CVE-2015-8139 | — | — | 5.8% | Jan 30, 2017 | ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecifie... |
| CVE-2015-8138 | — | — | 6.1% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packe... |
| CVE-2015-7979 | — | — | 12.0% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server associati... |
| CVE-2015-7978 | — | — | 10.0% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via... |
| CVE-2015-7976 | — | — | 3.5% | Jan 30, 2017 | The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter... |
| CVE-2015-7975 | — | — | 0.6% | Jan 30, 2017 | The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, w... |
| CVE-2015-8862 | — | — | 1.4% | Jan 23, 2017 | mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by lever... |
| CVE-2015-8860 | — | — | 4.9% | Jan 23, 2017 | The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an ... |
| CVE-2015-8858 | — | — | 2.4% | Jan 23, 2017 | The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via craft... |
| CVE-2015-8855 | — | — | 6.4% | Jan 23, 2017 | The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long v... |
| CVE-2015-7743 | — | — | 1.3% | Jan 23, 2017 | XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to ... |
| CVE-2015-4626 | — | — | 1.4% | Jan 23, 2017 | B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the busine... |
| CVE-2015-8212 | — | — | 3.2% | Jan 19, 2017 | CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execut... |
| CVE-2015-8684 | — | — | 1.2% | Jan 18, 2017 | Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attack... |
| CVE-2015-8667 | — | — | 1.2% | Jan 18, 2017 | Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attack... |
| CVE-2015-3188 | — | — | 14.4% | Jan 13, 2017 | The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecifi... |
| CVE-2015-6501 | — | — | 1.2% | Jan 12, 2017 | Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect user... |
| CVE-2015-8020 | — | — | 1.4% | Jan 11, 2017 | Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions ... |
| CVE-2015-4594 | — | — | 6.2% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a... |
| CVE-2015-4593 | — | — | 3.4% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ... |
| CVE-2015-4592 | — | — | 3.3% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow... |
| CVE-2015-4591 | — | — | 5.1% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo... |
| CVE-2015-2868 | — | — | 6.8% | Jan 6, 2017 | An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS serv... |
| CVE-2015-2867 | — | — | 4.8% | Jan 6, 2017 | A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete co... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now