2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-5726The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of se...
CVE-2015-5208Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.
CVE-2015-5207Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load ...
CVE-2015-0571HIGH7.8The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contr...
CVE-2015-0570HIGH7.8Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver ...
CVE-2015-0569HIGH7.8Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka W...
CVE-2015-6552The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1...
CVE-2015-6551Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x thro...
CVE-2015-6550bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 ...
CVE-2015-8868Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remo...
CVE-2015-8863Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (cras...
CVE-2015-0858Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardif...
CVE-2015-0857Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1...
CVE-2015-8839MEDIUM5.1Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause...
CVE-2015-8830Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause...
CVE-2015-8746fs/nfs/nfs4proc.c in the NFS client in the Linux kernel before 4.2.2 does not properly initialize memory for migration r...
CVE-2015-8324The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data str...
CVE-2015-8019The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not ac...
CVE-2015-4178The fs_pin implementation in the Linux kernel before 4.0.5 does not ensure the internal consistency of a certain list da...
CVE-2015-4177The collect_mounts function in fs/namespace.c in the Linux kernel before 4.0.5 does not properly consider that it may ex...
CVE-2015-4176fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users t...
CVE-2015-4170Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-2013121...
CVE-2015-2686net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom...
CVE-2015-2672The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altin...
CVE-2015-1573The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interacti...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now