2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-7563HIGH8.8Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the aut...
CVE-2015-8666HIGH7.9Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
CVE-2015-7260HIGH7.8Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable f...
CVE-2015-6028HIGH8.8Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
CVE-2015-2889HIGH8.8Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a...
CVE-2015-8026HIGH7.8Heap-based buffer overflow in the verify_vbr_checksum function in exfatfsck in exfat-utils before 1.2.1 allows remote at...
CVE-2015-3884HIGH8.8Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) ...
CVE-2015-8994HIGH7.5An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache e...
CVE-2015-4057HIGH7.5The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon ...
CVE-2015-8971HIGH7.8Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window titl...
CVE-2015-8854HIGH7.5The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecif...
CVE-2015-8315HIGH7.5The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long versi...
CVE-2015-7848HIGH7.5An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a spec...
CVE-2015-8743HIGH7.1QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It co...
CVE-2015-8967HIGH7.8arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protec...
CVE-2015-8963HIGH7Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a d...
CVE-2015-8962HIGH7.3Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows loc...
CVE-2015-8961HIGH7.8The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain priv...
CVE-2015-8968HIGH8.8git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a use...
CVE-2015-3288HIGH7.8mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or ...
CVE-2015-8955HIGH7.3arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges o...
CVE-2015-0572HIGH7Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux...
CVE-2015-8960HIGH8.1The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values fo...
CVE-2015-0568HIGH7.8Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driv...
CVE-2015-5738HIGH7.5The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on L...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now