2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6833 | — | — | 4.8% | Jan 19, 2016 | Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.... |
| CVE-2015-6832 | — | — | 5.2% | Jan 19, 2016 | Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x be... |
| CVE-2015-5590 | — | — | 4.6% | Jan 19, 2016 | Stack-based buffer overflow in the phar_fix_filepath function in ext/phar/phar.c in PHP before 5.4.43, 5.5.x before 5.5.... |
| CVE-2015-7886 | — | — | 1.2% | Jan 18, 2016 | NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive v... |
| CVE-2015-5009 | — | — | 1.3% | Jan 18, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9... |
| CVE-2015-5008 | — | — | 1.7% | Jan 18, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9... |
| CVE-2015-5002 | — | — | 0.8% | Jan 18, 2016 | Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0 through 11.0.14 allows remote attackers to inject ar... |
| CVE-2015-4988 | — | — | 3.0% | Jan 18, 2016 | Directory traversal vulnerability in the replay server in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before ... |
| CVE-2015-4959 | — | — | 1.4% | Jan 18, 2016 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP16 allows remote... |
| CVE-2015-4942 | — | — | 1.7% | Jan 18, 2016 | IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a ... |
| CVE-2015-7470 | — | — | 1.1% | Jan 17, 2016 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-C... |
| CVE-2015-7469 | — | — | 0.9% | Jan 17, 2016 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-C... |
| CVE-2015-7468 | — | — | 0.9% | Jan 17, 2016 | Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-C... |
| CVE-2015-7467 | — | — | 0.6% | Jan 17, 2016 | Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational... |
| CVE-2015-7414 | — | — | 0.6% | Jan 17, 2016 | Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative E... |
| CVE-2015-4960 | — | — | 0.6% | Jan 17, 2016 | IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0... |
| CVE-2015-4958 | — | — | 0.3% | Jan 17, 2016 | IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0... |
| CVE-2015-6864 | — | — | 0.9% | Jan 16, 2016 | HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to th... |
| CVE-2015-6863 | — | — | 2.3% | Jan 16, 2016 | HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Inte... |
| CVE-2015-8749 | — | — | 2.2% | Jan 15, 2016 | The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1... |
| CVE-2015-8688 | — | — | 1.7% | Jan 15, 2016 | Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ sta... |
| CVE-2015-8685 | — | — | 1.7% | Jan 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inje... |
| CVE-2015-8675 | — | — | 0.3% | Jan 15, 2016 | Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, w... |
| CVE-2015-8281 | — | — | 3.8% | Jan 15, 2016 | Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations. |
| CVE-2015-8280 | — | — | 6.0% | Jan 15, 2016 | Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed er... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now