CVEs from 2015

7,261 normalized CVEs published or assigned in this year.

Total
7,261
critical
critical 1,306
high
high 1,666
medium
medium 3,617
low
low 554
% Critical
18.0%
% with KEV
0.6%
% with exploit
10.1%

Top vendors

Top products

  • firefox 4,609
  • flash_player 3,392
  • php 1,526
  • moodle 1,087
  • acrobat_reader 878
  • acrobat 878
  • safari 736
  • internet_explorer 712
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-0673 medium 4.0 11y ago Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bu…
CVE-2015-0271 medium 4.0 11y ago The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
CVE-2015-0661 medium 4.0 11y ago The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858.
CVE-2015-0620 medium 4.0 11y ago The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via P…
CVE-2015-1618 medium 4.0 11y ago The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to obtain sensitive password information via a crafted URL.
CVE-2015-1613 medium 4.0 11y ago RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
CVE-2015-0260 medium 4.0 11y ago RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.
CVE-2015-1608 medium 4.0 12y ago Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive crede…
CVE-2015-0517 medium 4.0 12y ago The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticat…
CVE-2015-1456 medium 4.0 12y ago Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.
CVE-2015-0432 medium 4.0 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
CVE-2015-0422 medium 4.0 12y ago Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote authenticated us…
CVE-2015-0417 medium 4.0 12y ago Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal F…
CVE-2015-0415 medium 4.0 12y ago Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Ses…
CVE-2015-0409 medium 4.0 12y ago Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
CVE-2015-0401 medium 4.0 12y ago Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 and 11.1.1.7 allows remote authenticated users to affect integrity via unknown ve…
CVE-2015-0399 medium 4.0 12y ago Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.2 and 11.1.1.7 allows remote authenticated users to affect confidential…
CVE-2015-0398 medium 4.0 12y ago Unspecified vulnerability in the Siebel Life Sciences component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Clinica…
CVE-2015-0394 medium 4.0 12y ago Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via unknown vector…
CVE-2015-0391 medium 4.0 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
CVE-2015-0388 medium 4.0 12y ago Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal F…
CVE-2015-0387 medium 4.0 12y ago Unspecified vulnerability in the Siebel Core - Server OM Services component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via vectors related to Sec…
CVE-2015-0363 medium 4.0 12y ago Unspecified vulnerability in the Siebel Core EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect availability via unknown vectors related to Integration Bus…
CVE-2015-7755 unknown 2.5 8mo ago Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
CVE-2015-2291 unknown 2.5 3y ago Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
CVE-2015-0016 unknown 2.5 4y ago Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
CVE-2015-4495 unknown 2.5 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-1427 unknown 2.5 4y ago The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2015-0311 unknown 2.5 4y ago Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-5122 unknown 2.5 4y ago Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
CVE-2015-0313 unknown 2.5 4y ago Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-3113 unknown 2.5 4y ago Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-2426 unknown 2.5 4y ago A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
CVE-2015-2419 unknown 2.5 4y ago JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2015-3035 unknown 2.5 4y ago Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
CVE-2015-1187 unknown 2.5 4y ago The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
CVE-2015-3043 unknown 2.5 4y ago A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2015-1701 unknown 2.5 4y ago An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
CVE-2015-5119 unknown 2.5 4y ago A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2015-7645 unknown 2.5 4y ago Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
CVE-2015-2051 unknown 2.5 4y ago D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
CVE-2015-1635 unknown 2.5 4y ago Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
CVE-2015-1130 unknown 2.5 4y ago The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
CVE-2015-7450 unknown 2.5 5y ago Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
CVE-2015-4852 unknown 2.5 5y ago Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
CVE-2015-8651 unknown 1.5 4y ago Integer overflow in Adobe Flash Player allows attackers to execute code.
CVE-2015-2360 unknown 1.5 4y ago Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
CVE-2015-2425 unknown 1.5 4y ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2015-1769 unknown 1.5 4y ago A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
CVE-2015-6175 unknown 1.5 4y ago The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
CVE-2015-1671 unknown 1.5 4y ago A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
CVE-2015-0071 unknown 1.5 4y ago Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.
CVE-2015-0310 unknown 1.5 4y ago Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
CVE-2015-5317 unknown 1.5 4y ago Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
CVE-2015-2502 unknown 1.5 4y ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
CVE-2015-5123 unknown 1.5 4y ago Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
CVE-2015-1770 unknown 1.5 4y ago Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
CVE-2015-4068 unknown 1.5 4y ago Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
CVE-2015-0666 unknown 1.5 4y ago Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
CVE-2015-2546 unknown 1.5 4y ago The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
CVE-2015-2387 unknown 1.5 4y ago ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.
CVE-2015-2424 unknown 1.5 4y ago Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
CVE-2015-2590 unknown 1.5 4y ago An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
CVE-2015-2545 unknown 1.5 4y ago Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
CVE-2015-1642 unknown 1.5 4y ago Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
CVE-2015-4902 unknown 1.5 4y ago Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
CVE-2015-1641 unknown 1.5 5y ago Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context…
CVE-2015-6815 unknown The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of ser…
CVE-2015-5278 unknown The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors r…
CVE-2015-9289 unknown In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the usersp…
CVE-2015-9016 unknown In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead…
CVE-2015-5745 unknown Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control …
CVE-2015-20001 unknown In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of generic elements inside sift_up or sift_down_range …
CVE-2015-5239 unknown Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
CVE-2015-5160 unknown libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
CVE-2015-5230 unknown The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via crafted query packets.
CVE-2015-2309 unknown 2y ago Symfony has unsafe methods in the Request class
CVE-2015-8371 unknown 3y ago Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because o…
CVE-2015-8031 unknown 4y ago Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2
CVE-2015-5298 unknown 4y ago Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
CVE-2015-9543 unknown 4y ago An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs …
CVE-2015-1809 unknown 4y ago XML external entity (XXE) vulnerability in Jenkins
CVE-2015-1811 unknown 4y ago XML external entity (XXE) vulnerability in Jenkins
CVE-2015-6420 unknown 6y ago Insecure Deserialization in Apache Commons Collection
CVE-2015-7559 unknown 7y ago Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ