2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2015-6027MEDIUM6.1Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
CVE-2015-8985MEDIUM5.9The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a deni...
CVE-2015-7313MEDIUM5.5LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted t...
CVE-2015-4645MEDIUM5.5Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers...
CVE-2015-8896MEDIUM6.5Integer truncation issue in coders/pict.c in ImageMagick before 7.0.5-0 allows remote attackers to cause a denial of ser...
CVE-2015-6671MEDIUM5.9Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it eas...
CVE-2015-8903MEDIUM6.5The ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a ...
CVE-2015-8902MEDIUM6.5The ReadBlobByte function in coders/pdb.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a deni...
CVE-2015-8901MEDIUM6.5ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted M...
CVE-2015-8900MEDIUM5.5The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of servic...
CVE-2015-4056MEDIUM6.7The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which mak...
CVE-2015-8750MEDIUM6.5libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) ...
CVE-2015-5013MEDIUM5.5The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which...
CVE-2015-7977MEDIUM5.9ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer de...
CVE-2015-7973MEDIUM6.5NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to con...
CVE-2015-8861MEDIUM6.1The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by...
CVE-2015-8859MEDIUM5.3The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
CVE-2015-8856MEDIUM6.1Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to ...
CVE-2015-8818MEDIUM5.5The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO r...
CVE-2015-8745MEDIUM5.5QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It ...
CVE-2015-8744MEDIUM5.5QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It ...
CVE-2015-8701MEDIUM6.5QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happen...
CVE-2015-8558MEDIUM5.5The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of ser...
CVE-2015-3152MEDIUM5.9Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the...
CVE-2015-8839MEDIUM5.1Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now