2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7029 | — | — | 3.9% | Jul 3, 2016 | Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attacker... |
| CVE-2015-6931 | — | — | 0.8% | Jul 3, 2016 | Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U... |
| CVE-2015-8801 | — | — | 0.3% | Jun 30, 2016 | Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass inte... |
| CVE-2015-8899 | — | — | 2.4% | Jun 30, 2016 | Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address tha... |
| CVE-2015-8699 | — | — | 1.8% | Jun 29, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 be... |
| CVE-2015-8698 | — | — | 0.6% | Jun 29, 2016 | CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5... |
| CVE-2015-7473 | — | — | 0.3% | Jun 26, 2016 | runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restri... |
| CVE-2015-7988 | — | — | 4.8% | Jun 26, 2016 | The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary cod... |
| CVE-2015-7987 | — | — | 2.5% | Jun 26, 2016 | Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memo... |
| CVE-2015-6289 | — | — | 4.4% | Jun 23, 2016 | Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a deni... |
| CVE-2015-8289 | — | — | 2.2% | Jun 20, 2016 | The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 a... |
| CVE-2015-8288 | — | — | 1.9% | Jun 20, 2016 | NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded... |
| CVE-2015-7776 | — | — | 1.3% | Jun 19, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for rem... |
| CVE-2015-7462 | — | — | 0.2% | Jun 19, 2016 | IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords with... |
| CVE-2015-7775 | — | — | 0.8% | Jun 19, 2016 | Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary we... |
| CVE-2015-8914 | — | — | 4.2% | Jun 17, 2016 | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an int... |
| CVE-2015-8869 | — | — | 5.2% | Jun 13, 2016 | OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow a... |
| CVE-2015-8268 | — | — | 3.0% | Jun 10, 2016 | The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary ... |
| CVE-2015-1797 | — | — | — | Jun 9, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-7695 | — | — | 3.0% | Jun 7, 2016 | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attacke... |
| CVE-2015-7611 | — | — | 68.6% | Jun 7, 2016 | Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst... |
| CVE-2015-5723 | — | — | 0.4% | Jun 7, 2016 | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1... |
| CVE-2015-5261 | — | — | 0.5% | Jun 7, 2016 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations ... |
| CVE-2015-5260 | — | — | 0.6% | Jun 7, 2016 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory ... |
| CVE-2015-5231 | — | — | 0.4% | Jun 7, 2016 | The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obta... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now