2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8963 | HIGH | 7 | 1.4% | Nov 16, 2016 | Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a d... |
| CVE-2015-8962 | HIGH | 7.3 | 1.8% | Nov 16, 2016 | Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows loc... |
| CVE-2015-8961 | HIGH | 7.8 | 2.0% | Nov 16, 2016 | The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain priv... |
| CVE-2015-8969 | CRITICAL | 9.8 | 4.8% | Nov 3, 2016 | git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious... |
| CVE-2015-8968 | HIGH | 8.8 | 5.2% | Nov 3, 2016 | git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a use... |
| CVE-2015-0787 | — | — | 0.8% | Oct 27, 2016 | XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the ac... |
| CVE-2015-8953 | — | — | 0.5% | Oct 16, 2016 | fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to... |
| CVE-2015-8952 | — | — | 0.5% | Oct 16, 2016 | The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr bloc... |
| CVE-2015-3288 | HIGH | 7.8 | 0.5% | Oct 16, 2016 | mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or ... |
| CVE-2015-8956 | — | — | 0.2% | Oct 10, 2016 | The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain... |
| CVE-2015-8955 | HIGH | 7.3 | 0.2% | Oct 10, 2016 | arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges o... |
| CVE-2015-8951 | — | — | 0.5% | Oct 10, 2016 | Multiple use-after-free vulnerabilities in sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm sound driver in Androi... |
| CVE-2015-8950 | — | — | 1.5% | Oct 10, 2016 | arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products... |
| CVE-2015-0572 | HIGH | 7 | 0.3% | Oct 10, 2016 | Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux... |
| CVE-2015-7363 | — | — | 0.7% | Oct 7, 2016 | Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.... |
| CVE-2015-5162 | — | — | 3.1% | Oct 7, 2016 | The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.... |
| CVE-2015-2080 | — | — | 74.9% | Oct 7, 2016 | The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive informat... |
| CVE-2015-1000013 | — | — | 2.0% | Oct 6, 2016 | Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 |
| CVE-2015-1000012 | — | — | 9.3% | Oct 6, 2016 | Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin |
| CVE-2015-1000011 | — | — | 2.6% | Oct 6, 2016 | Blind SQL Injection in wordpress plugin dukapress v2.5.9 |
| CVE-2015-1000010 | — | — | 7.0% | Oct 6, 2016 | Remote file download in simple-image-manipulator v1.0 wordpress plugin |
| CVE-2015-1000009 | — | — | 2.2% | Oct 6, 2016 | Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 |
| CVE-2015-1000008 | — | — | 2.1% | Oct 6, 2016 | Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2 |
| CVE-2015-1000007 | — | — | 2.3% | Oct 6, 2016 | Remote file download vulnerability in wptf-image-gallery v1.03 |
| CVE-2015-1000006 | — | — | 3.9% | Oct 6, 2016 | Remote file download vulnerability in recent-backups v0.7 wordpress plugin |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now