2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5947 | HIGH | 8.1 | 2.7% | Sep 6, 2017 | SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. |
| CVE-2015-0853 | HIGH | 8.8 | 3.3% | Sep 6, 2017 | svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by usi... |
| CVE-2015-5958 | HIGH | 8.8 | 27.4% | Aug 31, 2017 | phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL. |
| CVE-2015-3655 | HIGH | 8.8 | 0.7% | Aug 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before... |
| CVE-2015-0928 | HIGH | 7.5 | 2.3% | Aug 28, 2017 | libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference). |
| CVE-2015-5258 | HIGH | 8.8 | 0.8% | Aug 22, 2017 | Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3. |
| CVE-2015-3649 | HIGH | 7.8 | 0.4% | Aug 18, 2017 | The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp contain... |
| CVE-2015-2291 | HIGH | 7.8 | 9.0% | Aug 9, 2017 | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all... |
| CVE-2015-7764 | HIGH | 7.5 | 1.5% | Aug 9, 2017 | Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode. |
| CVE-2015-7854 | HIGH | 8.8 | 14.6% | Aug 7, 2017 | Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows rem... |
| CVE-2015-7849 | HIGH | 8.8 | 16.8% | Aug 7, 2017 | Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated us... |
| CVE-2015-7704 | HIGH | 7.5 | 10.9% | Aug 7, 2017 | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service v... |
| CVE-2015-7701 | HIGH | 7.5 | 6.5% | Aug 7, 2017 | Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote atta... |
| CVE-2015-7692 | HIGH | 7.5 | 7.3% | Aug 7, 2017 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a... |
| CVE-2015-7691 | HIGH | 7.5 | 7.2% | Aug 7, 2017 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a... |
| CVE-2015-7703 | HIGH | 7.5 | 3.9% | Jul 24, 2017 | The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configur... |
| CVE-2015-5219 | HIGH | 7.5 | 5.9% | Jul 21, 2017 | The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value... |
| CVE-2015-5232 | HIGH | 8.1 | 1.7% | Jun 7, 2017 | Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197. |
| CVE-2015-3191 | HIGH | 8.8 | 0.5% | May 25, 2017 | With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo... |
| CVE-2015-5436 | HIGH | 7.5 | 1.6% | May 11, 2017 | A potential security vulnerability has been identified with HP Integrated Lights-Out 4 (iLO 4) firmware version 2.11 and... |
| CVE-2015-9004 | HIGH | 7.8 | 0.8% | May 2, 2017 | kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privi... |
| CVE-2015-8619 | HIGH | 7.5 | 3.9% | Apr 13, 2017 | The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write an... |
| CVE-2015-8567 | HIGH | 7.7 | 5.6% | Apr 13, 2017 | Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). |
| CVE-2015-4646 | HIGH | 7.5 | 6.9% | Apr 13, 2017 | (1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attack... |
| CVE-2015-7563 | HIGH | 8.8 | 3.1% | Apr 12, 2017 | Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the aut... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now