2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1583HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentica...
CVE-2015-5361MEDIUM6.5Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open relate...
CVE-2015-3006MEDIUM6.5On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the de...
CVE-2015-2992MEDIUM6.1Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
CVE-2015-5686HIGH8.8Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request For...
CVE-2015-5201HIGH7.5VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x be...
CVE-2015-0565CRITICAL10NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
CVE-2015-9542HIGH7.5add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is ...
CVE-2015-4411HIGH7.5The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attacker...
CVE-2015-4410HIGH7.5The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows re...
CVE-2015-2923MEDIUM6.5The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to...
CVE-2015-7747HIGH8.8Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted...
CVE-2015-2104Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-9543LOW3.3An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak console...
CVE-2015-0749MEDIUM6.1A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cro...
CVE-2015-7507HIGH7.5libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a ...
CVE-2015-7567CRITICAL9.8SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passw...
CVE-2015-7505HIGH8.8Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attack...
CVE-2015-7506MEDIUM6.5The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of servic...
CVE-2015-6970CRITICAL9.8The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows r...
CVE-2015-1425CRITICAL9.8JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities
CVE-2015-8751HIGH8.8Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impa...
CVE-2015-5216MEDIUM6.1The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python...
CVE-2015-5215MEDIUM6.1The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 bef...
CVE-2015-4715MEDIUM4.9The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now