2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-5667Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is e...
CVE-2015-8030SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted (1) U3D, (2) LWO, ...
CVE-2015-8029SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted Filmbox document, ...
CVE-2015-8028Multiple buffer overflows in SAP 3D Visual Enterprise Viewer (VEV) allow remote attackers to execute arbitrary code via ...
CVE-2015-7972The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_...
CVE-2015-7971Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hype...
CVE-2015-7970The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which a...
CVE-2015-7969Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to ca...
CVE-2015-7835The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entrie...
CVE-2015-7814Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6.x and earlier allows local domains with...
CVE-2015-7813Xen 4.4.x, 4.5.x, and 4.6.x does not limit the number of printk console messages when reporting unimplemented hypercalls...
CVE-2015-6352Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempt...
CVE-2015-6351Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices with software 19.1.0.61559 and 19.2.0 allow remote at...
CVE-2015-6350SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users t...
CVE-2015-6349Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Serv...
CVE-2015-6348The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows ...
CVE-2015-6347The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass in...
CVE-2015-6346Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers t...
CVE-2015-6345SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote a...
CVE-2015-6344The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authent...
CVE-2015-7899The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obt...
CVE-2015-7859The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers...
CVE-2015-7858SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un...
CVE-2015-7857SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p...
CVE-2015-7713OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now