2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8971 | HIGH | 7.8 | 1.1% | Jan 23, 2017 | Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window titl... |
| CVE-2015-8862 | — | — | 1.4% | Jan 23, 2017 | mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by lever... |
| CVE-2015-8861 | MEDIUM | 6.1 | 3.0% | Jan 23, 2017 | The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by... |
| CVE-2015-8860 | — | — | 4.9% | Jan 23, 2017 | The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an ... |
| CVE-2015-8859 | MEDIUM | 5.3 | 4.7% | Jan 23, 2017 | The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors. |
| CVE-2015-8858 | — | — | 2.4% | Jan 23, 2017 | The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via craft... |
| CVE-2015-8857 | CRITICAL | 9.8 | 3.6% | Jan 23, 2017 | The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean ... |
| CVE-2015-8856 | MEDIUM | 6.1 | 2.5% | Jan 23, 2017 | Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to ... |
| CVE-2015-8855 | — | — | 6.4% | Jan 23, 2017 | The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long v... |
| CVE-2015-8854 | HIGH | 7.5 | 4.3% | Jan 23, 2017 | The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecif... |
| CVE-2015-8315 | HIGH | 7.5 | 6.8% | Jan 23, 2017 | The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long versi... |
| CVE-2015-7743 | — | — | 1.3% | Jan 23, 2017 | XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to ... |
| CVE-2015-4626 | — | — | 1.4% | Jan 23, 2017 | B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the busine... |
| CVE-2015-8212 | — | — | 3.2% | Jan 19, 2017 | CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execut... |
| CVE-2015-8684 | — | — | 1.2% | Jan 18, 2017 | Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attack... |
| CVE-2015-8667 | — | — | 1.2% | Jan 18, 2017 | Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attack... |
| CVE-2015-3188 | — | — | 14.4% | Jan 13, 2017 | The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecifi... |
| CVE-2015-6501 | — | — | 1.2% | Jan 12, 2017 | Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect user... |
| CVE-2015-8020 | — | — | 1.4% | Jan 11, 2017 | Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions ... |
| CVE-2015-4594 | — | — | 6.2% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a... |
| CVE-2015-4593 | — | — | 3.4% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ... |
| CVE-2015-4592 | — | — | 3.3% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow... |
| CVE-2015-4591 | — | — | 5.1% | Jan 10, 2017 | eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo... |
| CVE-2015-7848 | HIGH | 7.5 | 6.1% | Jan 6, 2017 | An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a spec... |
| CVE-2015-2868 | — | — | 6.8% | Jan 6, 2017 | An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS serv... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now