2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2015-0796MEDIUM6.3In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could ...
CVE-2015-5532MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPr...
CVE-2015-1239MEDIUM6.5Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, ...
CVE-2015-1828MEDIUM5.9The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtai...
CVE-2015-6748MEDIUM6.1Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
CVE-2015-4707MEDIUM6.1Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or...
CVE-2015-1865MEDIUM5.1fts.c in coreutils 8.4 allows local users to delete arbitrary files.
CVE-2015-9230MEDIUM4.8In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPres...
CVE-2015-9229MEDIUM4.8In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for ...
CVE-2015-8079MEDIUM5.3qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.
CVE-2015-3163MEDIUM4.3The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote...
CVE-2015-7855MEDIUM6.5The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause ...
CVE-2015-7852MEDIUM5.9ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) v...
CVE-2015-7850MEDIUM6.5ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service...
CVE-2015-7702MEDIUM6.5The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a...
CVE-2015-3171MEDIUM5.5sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ ...
CVE-2015-9101MEDIUM5.5The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, ...
CVE-2015-8538MEDIUM6.5dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).
CVE-2015-3190MEDIUM6.1With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo...
CVE-2015-1834MEDIUM6.5A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release ve...
CVE-2015-8959MEDIUM6.5coders/dds.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (CPU consumption) v...
CVE-2015-8345MEDIUM6.5The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash an...
CVE-2015-8613MEDIUM6.5Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulati...
CVE-2015-8568MEDIUM6.5Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to caus...
CVE-2015-8504MEDIUM6.5Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic excep...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now