2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5228 | — | — | 0.4% | Jun 7, 2016 | The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and... |
| CVE-2015-5041 | — | — | 3.9% | Jun 6, 2016 | The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 bef... |
| CVE-2015-8872 | — | — | 0.4% | Jun 3, 2016 | The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a de... |
| CVE-2015-8875 | — | — | 2.8% | Jun 1, 2016 | Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_proce... |
| CVE-2015-7360 | — | — | 1.5% | May 26, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.... |
| CVE-2015-8853 | — | — | 2.6% | May 25, 2016 | The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-depe... |
| CVE-2015-8878 | — | — | 1.2% | May 22, 2016 | main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows ... |
| CVE-2015-8877 | — | — | 3.6% | May 22, 2016 | The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in P... |
| CVE-2015-8876 | — | — | 7.7% | May 22, 2016 | Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exce... |
| CVE-2015-8867 | — | — | 4.4% | May 22, 2016 | The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x b... |
| CVE-2015-8834 | — | — | 1.8% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to i... |
| CVE-2015-7989 | — | — | 2.1% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated us... |
| CVE-2015-5715 | — | — | 6.3% | May 22, 2016 | The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 all... |
| CVE-2015-5714 | — | — | 6.4% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web scrip... |
| CVE-2015-7558 | — | — | 2.4% | May 20, 2016 | librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption... |
| CVE-2015-7557 | — | — | 2.1% | May 20, 2016 | The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to ... |
| CVE-2015-8865 | — | — | 5.0% | May 20, 2016 | The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.... |
| CVE-2015-8874 | — | — | 8.3% | May 16, 2016 | Stack consumption vulnerability in GD in PHP before 5.6.12 allows remote attackers to cause a denial of service via a cr... |
| CVE-2015-8838 | — | — | 1.7% | May 16, 2016 | ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mea... |
| CVE-2015-8835 | — | — | 6.2% | May 16, 2016 | The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5... |
| CVE-2015-6838 | — | — | 7.3% | May 16, 2016 | The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before... |
| CVE-2015-6837 | — | — | 6.6% | May 16, 2016 | The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before... |
| CVE-2015-6835 | — | — | 37.0% | May 16, 2016 | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_... |
| CVE-2015-6834 | — | — | 46.8% | May 16, 2016 | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote ... |
| CVE-2015-5589 | — | — | 6.3% | May 16, 2016 | The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now