2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8608 | — | — | 4.6% | Feb 7, 2017 | The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of... |
| CVE-2015-5677 | — | — | 0.5% | Feb 7, 2017 | bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows l... |
| CVE-2015-2794 | — | — | 74.6% | Feb 6, 2017 | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S... |
| CVE-2015-0229 | — | — | — | Feb 4, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
| CVE-2015-4049 | — | — | 0.9% | Feb 3, 2017 | Unisys Libra 43xx, 63xx, and 83xx, and FS600 class systems with MCP-FIRMWARE 40.0 before 40.0IC4 Build 270 might allow r... |
| CVE-2015-8977 | — | — | 2.2% | Jan 31, 2017 | MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attacker... |
| CVE-2015-8976 | — | — | 1.0% | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Mer... |
| CVE-2015-8975 | — | — | 1.7% | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x befo... |
| CVE-2015-8974 | — | — | 2.1% | Jan 31, 2017 | SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) befo... |
| CVE-2015-8973 | — | — | 1.6% | Jan 31, 2017 | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows... |
| CVE-2015-8034 | — | — | 0.4% | Jan 30, 2017 | The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obta... |
| CVE-2015-7331 | — | — | 1.2% | Jan 30, 2017 | The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vecto... |
| CVE-2015-2181 | — | — | 2.9% | Jan 30, 2017 | Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers t... |
| CVE-2015-2180 | — | — | 4.7% | Jan 30, 2017 | The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands... |
| CVE-2015-8158 | — | — | 7.6% | Jan 30, 2017 | The getresponse function in ntpq in NTP versions before 4.2.8p9 and 4.3.x before 4.3.90 allows remote attackers to cause... |
| CVE-2015-8140 | — | — | 4.6% | Jan 30, 2017 | The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sniffing the network. |
| CVE-2015-8139 | — | — | 5.8% | Jan 30, 2017 | ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecifie... |
| CVE-2015-8138 | — | — | 6.1% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packe... |
| CVE-2015-7979 | — | — | 12.0% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server associati... |
| CVE-2015-7978 | — | — | 10.0% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via... |
| CVE-2015-7977 | MEDIUM | 5.9 | 6.3% | Jan 30, 2017 | ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer de... |
| CVE-2015-7976 | — | — | 3.5% | Jan 30, 2017 | The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter... |
| CVE-2015-7975 | — | — | 0.6% | Jan 30, 2017 | The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, w... |
| CVE-2015-7973 | MEDIUM | 6.5 | 3.3% | Jan 30, 2017 | NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to con... |
| CVE-2015-8972 | CRITICAL | 9.8 | 3.8% | Jan 23, 2017 | Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 mi... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now