2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8361 | — | — | 2.8% | Feb 8, 2016 | Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, w... |
| CVE-2015-8360 | — | — | 3.0% | Feb 8, 2016 | An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arb... |
| CVE-2015-3252 | — | — | 2.2% | Feb 8, 2016 | Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allow... |
| CVE-2015-3251 | — | — | 2.5% | Feb 8, 2016 | Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information ... |
| CVE-2015-2012 | — | — | 0.4% | Feb 8, 2016 | The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 us... |
| CVE-2015-8767 | — | — | 0.4% | Feb 8, 2016 | net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a s... |
| CVE-2015-8709 | — | — | 0.4% | Feb 8, 2016 | kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain priv... |
| CVE-2015-8575 | — | — | 0.5% | Feb 8, 2016 | The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, wh... |
| CVE-2015-7566 | — | — | 1.8% | Feb 8, 2016 | The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate a... |
| CVE-2015-7550 | — | — | 0.4% | Feb 8, 2016 | The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphor... |
| CVE-2015-6398 | — | — | 1.9% | Feb 7, 2016 | Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attac... |
| CVE-2015-7915 | — | — | 2.5% | Feb 6, 2016 | Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sen... |
| CVE-2015-7914 | — | — | 2.3% | Feb 6, 2016 | Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge... |
| CVE-2015-6553 | — | — | — | Feb 5, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further in... |
| CVE-2015-2303 | — | — | — | Feb 5, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6406. Reason: This candidate is a reservation ... |
| CVE-2015-2302 | — | — | — | Feb 5, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6405. Reason: This candidate is a reservation ... |
| CVE-2015-8269 | — | — | 2.3% | Feb 4, 2016 | The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by... |
| CVE-2015-8748 | — | — | 2.2% | Feb 3, 2016 | Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacha... |
| CVE-2015-8747 | — | — | 2.9% | Feb 3, 2016 | The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files v... |
| CVE-2015-7539 | — | — | 1.4% | Feb 3, 2016 | The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced... |
| CVE-2015-7538 | — | — | 2.2% | Feb 3, 2016 | Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecifi... |
| CVE-2015-7537 | — | — | 2.4% | Feb 3, 2016 | Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers t... |
| CVE-2015-7536 | — | — | 1.3% | Feb 3, 2016 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated user... |
| CVE-2015-5344 | — | — | 7.1% | Feb 3, 2016 | The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arb... |
| CVE-2015-8265 | — | — | 1.9% | Feb 1, 2016 | Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with softwar... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now