2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2867 | — | — | 4.8% | Jan 6, 2017 | A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete co... |
| CVE-2015-3441 | — | — | 2.0% | Jan 5, 2017 | The Parental Control panel in Genexis devices with DRGOS before 1.14.1 allows remote authenticated users to execute arbi... |
| CVE-2015-8818 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO r... |
| CVE-2015-8817 | — | — | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerabl... |
| CVE-2015-8745 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It ... |
| CVE-2015-8744 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It ... |
| CVE-2015-8743 | HIGH | 7.1 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It co... |
| CVE-2015-8701 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happen... |
| CVE-2015-0854 | — | — | 2.5% | Dec 29, 2016 | App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via... |
| CVE-2015-6574 | — | — | 5.4% | Dec 15, 2016 | The SNAP Lite component in certain SISCO MMS-EASE and AX-S4 ICCP products allows remote attackers to cause a denial of s... |
| CVE-2015-3271 | — | — | 6.5% | Dec 15, 2016 | Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTT... |
| CVE-2015-8542 | — | — | 2.2% | Dec 15, 2016 | An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP... |
| CVE-2015-5073 | — | — | 7.7% | Dec 13, 2016 | Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attacker... |
| CVE-2015-3418 | — | — | 2.3% | Dec 13, 2016 | The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers... |
| CVE-2015-3217 | — | — | 6.2% | Dec 13, 2016 | PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cau... |
| CVE-2015-3210 | CRITICAL | 9.8 | 9.2% | Dec 13, 2016 | Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code v... |
| CVE-2015-8786 | — | — | 3.5% | Dec 9, 2016 | The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a deni... |
| CVE-2015-8967 | HIGH | 7.8 | 0.8% | Dec 8, 2016 | arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protec... |
| CVE-2015-8966 | — | — | 0.5% | Dec 8, 2016 | arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1)... |
| CVE-2015-8870 | — | — | 2.0% | Dec 6, 2016 | Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-... |
| CVE-2015-8970 | — | — | 0.5% | Nov 28, 2016 | crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on a... |
| CVE-2015-1328 | — | — | 37.7% | Nov 28, 2016 | The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no... |
| CVE-2015-4961 | — | — | 0.5% | Nov 24, 2016 | IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.11... |
| CVE-2015-8978 | — | — | 1.5% | Nov 22, 2016 | In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more... |
| CVE-2015-8964 | — | — | 1.5% | Nov 16, 2016 | The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtai... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now