2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-8666HIGH7.9Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
CVE-2015-7260HIGH7.8Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable f...
CVE-2015-6028HIGH8.8Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
CVE-2015-2889HIGH8.8Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a...
CVE-2015-8026HIGH7.8Heap-based buffer overflow in the verify_vbr_checksum function in exfatfsck in exfat-utils before 1.2.1 allows remote at...
CVE-2015-3884HIGH8.8Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) ...
CVE-2015-8994HIGH7.5An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache e...
CVE-2015-4057HIGH7.5The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon ...
CVE-2015-8971HIGH7.8Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window titl...
CVE-2015-8854HIGH7.5The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecif...
CVE-2015-8315HIGH7.5The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long versi...
CVE-2015-7848HIGH7.5An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a spec...
CVE-2015-8743HIGH7.1QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It co...
CVE-2015-8967HIGH7.8arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protec...
CVE-2015-8963HIGH7Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a d...
CVE-2015-8962HIGH7.3Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows loc...
CVE-2015-8961HIGH7.8The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain priv...
CVE-2015-8968HIGH8.8git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a use...
CVE-2015-3288HIGH7.8mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or ...
CVE-2015-8955HIGH7.3arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges o...
CVE-2015-0572HIGH7Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux...
CVE-2015-8960HIGH8.1The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values fo...
CVE-2015-0568HIGH7.8Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driv...
CVE-2015-5738HIGH7.5The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on L...
CVE-2015-8800HIGH7.3Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical Syste...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now