2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8758 | — | — | 1.1% | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and ... |
| CVE-2015-8757 | — | — | 1.4% | Jan 8, 2016 | Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allo... |
| CVE-2015-8756 | — | — | 0.8% | Jan 8, 2016 | Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in T... |
| CVE-2015-8755 | — | — | 1.1% | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7... |
| CVE-2015-8754 | — | — | 1.3% | Jan 8, 2016 | The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and ... |
| CVE-2015-8753 | — | — | 2.1% | Jan 8, 2016 | SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a craft... |
| CVE-2015-8615 | — | — | 1.2% | Jan 8, 2016 | The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages ... |
| CVE-2015-8612 | — | — | 6.3% | Jan 8, 2016 | The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users... |
| CVE-2015-8597 | — | — | 1.9% | Jan 8, 2016 | Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might ... |
| CVE-2015-8547 | — | — | 2.8% | Jan 8, 2016 | The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to ... |
| CVE-2015-8481 | — | — | 1.3% | Jan 8, 2016 | Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong ima... |
| CVE-2015-8303 | — | — | 0.2% | Jan 8, 2016 | Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closi... |
| CVE-2015-8226 | — | — | 0.7% | Jan 8, 2016 | The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL0... |
| CVE-2015-8225 | — | — | 0.7% | Jan 8, 2016 | The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL0... |
| CVE-2015-7758 | — | — | 0.4% | Jan 8, 2016 | Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the na... |
| CVE-2015-7754 | — | — | 3.9% | Jan 8, 2016 | Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of s... |
| CVE-2015-7554 | — | — | 4.2% | Jan 8, 2016 | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory ... |
| CVE-2015-7519 | — | — | 2.4% | Jan 8, 2016 | agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache in... |
| CVE-2015-7362 | — | — | 0.4% | Jan 8, 2016 | Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable ... |
| CVE-2015-7328 | — | — | 0.2% | Jan 8, 2016 | Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permission... |
| CVE-2015-6856 | — | — | 0.5% | Jan 8, 2016 | Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locati... |
| CVE-2015-5259 | — | — | 57.0% | Jan 8, 2016 | Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows r... |
| CVE-2015-5254 | — | — | 37.9% | Jan 8, 2016 | Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remot... |
| CVE-2015-8261 | — | — | 3.5% | Jan 8, 2016 | The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized... |
| CVE-2015-6862 | — | — | 1.4% | Jan 8, 2016 | HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrict... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now