2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8683 | — | — | 2.9% | Apr 13, 2016 | The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service... |
| CVE-2015-8665 | — | — | 2.9% | Apr 13, 2016 | tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via the Sample... |
| CVE-2015-3146 | — | — | 3.9% | Apr 13, 2016 | The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not proper... |
| CVE-2015-1547 | — | — | 3.4% | Apr 13, 2016 | The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized mem... |
| CVE-2015-8807 | — | — | 2.1% | Apr 13, 2016 | Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/U... |
| CVE-2015-8843 | — | — | 0.7% | Apr 13, 2016 | The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an... |
| CVE-2015-8606 | — | — | 1.5% | Apr 13, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1... |
| CVE-2015-8555 | — | — | 2.3% | Apr 13, 2016 | Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not ... |
| CVE-2015-8552 | — | — | 0.4% | Apr 13, 2016 | The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, a... |
| CVE-2015-7555 | — | — | 1.5% | Apr 13, 2016 | Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program ... |
| CVE-2015-7545 | — | — | 20.1% | Apr 13, 2016 | The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x... |
| CVE-2015-0861 | — | — | 1.1% | Apr 13, 2016 | model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 all... |
| CVE-2015-8682 | — | — | 0.5% | Apr 13, 2016 | The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B35... |
| CVE-2015-8304 | — | — | 1.4% | Apr 13, 2016 | Integer overflow in Huawei P7 phones with software before P7-L07 V100R001C01B606 allows remote attackers to gain privile... |
| CVE-2015-7520 | — | — | 5.2% | Apr 12, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apac... |
| CVE-2015-5347 | — | — | 8.2% | Apr 12, 2016 | Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.ma... |
| CVE-2015-8702 | — | — | 2.3% | Apr 12, 2016 | The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service ... |
| CVE-2015-8537 | — | — | 1.9% | Apr 12, 2016 | app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attac... |
| CVE-2015-8474 | — | — | 1.8% | Apr 12, 2016 | Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine befor... |
| CVE-2015-8473 | — | — | 1.7% | Apr 12, 2016 | The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to ... |
| CVE-2015-8346 | — | — | 1.9% | Apr 12, 2016 | app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attac... |
| CVE-2015-8021 | — | — | 1.4% | Apr 12, 2016 | Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Control... |
| CVE-2015-5167 | — | — | 1.9% | Apr 12, 2016 | The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrict... |
| CVE-2015-3268 | — | — | 9.2% | Apr 12, 2016 | Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apach... |
| CVE-2015-8833 | — | — | 7.0% | Apr 12, 2016 | Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pid... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now