2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8360——An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arb...
CVE-2015-3252——Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allow...
CVE-2015-3251——Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information ...
CVE-2015-2012——The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 us...
CVE-2015-8767——net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a s...
CVE-2015-8709——kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain priv...
CVE-2015-8575——The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, wh...
CVE-2015-7566——The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate a...
CVE-2015-7550——The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphor...
CVE-2015-6398——Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attac...
CVE-2015-7915——Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sen...
CVE-2015-7914——Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge...
CVE-2015-6553——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further in...
CVE-2015-2303——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6406. Reason: This candidate is a reservation ...
CVE-2015-2302——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6405. Reason: This candidate is a reservation ...
CVE-2015-8269——The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by...
CVE-2015-8748——Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacha...
CVE-2015-8747——The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files v...
CVE-2015-7539——The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced...
CVE-2015-7538——Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecifi...
CVE-2015-7537——Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers t...
CVE-2015-7536——Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated user...
CVE-2015-5344——The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arb...
CVE-2015-8265——Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with softwar...
CVE-2015-7923——Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easi...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now