2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8374fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obta...
CVE-2015-7990Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to c...
CVE-2015-7885The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a...
CVE-2015-7884The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initi...
CVE-2015-7509fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (syste...
CVE-2015-7783Cross-site scripting (XSS) vulnerability in Let's PHP! p++BBS before 4.10 allows remote attackers to inject arbitrary we...
CVE-2015-7665Tails before 1.7 includes the wget program but does not prevent automatic fallback from passive FTP to active FTP, which...
CVE-2015-6538The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attac...
CVE-2015-6537SQL injection vulnerability in the login page in Epiphany Cardio Server 3.3 allows remote attackers to execute arbitrary...
CVE-2015-8263NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it eas...
CVE-2015-8262Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in t...
CVE-2015-8254The Frontel protocol before 3 on RSI Video Technologies Videofied devices does not use integrity protection, which makes...
CVE-2015-8253The Frontel protocol before 3 on RSI Video Technologies Videofied devices sets up AES encryption but sends all traffic i...
CVE-2015-8252The Frontel protocol before 3 on RSI Video Technologies Videofied devices sends a cleartext serial number, which allows ...
CVE-2015-6005Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to injec...
CVE-2015-6004Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary ...
CVE-2015-8669libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 ...
CVE-2015-6409Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade atta...
CVE-2015-8664Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 4...
CVE-2015-6792The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remo...
CVE-2015-8663The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failur...
CVE-2015-8662The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposit...
CVE-2015-8661The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship...
CVE-2015-7934The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file path...
CVE-2015-7932Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now