2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8851HIGH7.5node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to hav...
CVE-2015-0949HIGH7.8The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revis...
CVE-2015-5483HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote a...
CVE-2015-8012HIGH7.5lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malfo...
CVE-2015-8011CRITICAL9.8Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to ...
CVE-2015-7851MEDIUM6.5Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used ...
CVE-2015-2249MEDIUM5.4Zimbra Collaboration before 8.6.0 patch5 has XSS.
CVE-2015-3154MEDIUM6.1CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x befo...
CVE-2015-0294HIGH7.5GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
CVE-2015-0244CRITICAL9.8PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not ...
CVE-2015-0243HIGH8.8Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3...
CVE-2015-0242HIGH8.8Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9....
CVE-2015-0241HIGH8.8The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4....
CVE-2015-4709Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-9541HIGH7.5Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlS...
CVE-2015-1203Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-1202Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-2929HIGH7.5The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6....
CVE-2015-2928HIGH7.5The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6....
CVE-2015-2689HIGH7.5Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during period...
CVE-2015-2688HIGH7.5buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffe...
CVE-2015-1530HIGH7.8media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_serve...
CVE-2015-1525MEDIUM5.5audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy appli...
CVE-2015-4042CRITICAL9.8Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to ...
CVE-2015-4041HIGH7.8The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculati...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now