2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8090——The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and ...
CVE-2015-8053——Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote at...
CVE-2015-8052——Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote at...
CVE-2015-8051——The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vecto...
CVE-2015-5255——Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before...
CVE-2015-8035——The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dep...
CVE-2015-8023——The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x befor...
CVE-2015-7942——The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it sto...
CVE-2015-7941——libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial o...
CVE-2015-5999——Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2...
CVE-2015-5253——The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authentica...
CVE-2015-6373——Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9...
CVE-2015-6372——Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating S...
CVE-2015-6847——The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log...
CVE-2015-6357——The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certific...
CVE-2015-6330——Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote at...
CVE-2015-8233——Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal ...
CVE-2015-8232——The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstan...
CVE-2015-8222——The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions f...
CVE-2015-8221——Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAM...
CVE-2015-8220——Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFi...
CVE-2015-7998——The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build ...
CVE-2015-7997——Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller...
CVE-2015-7996——The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 1...
CVE-2015-7995——The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which a...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now