2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-3150HIGH7.1abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files...
CVE-2015-3147MEDIUM6.5daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-up...
CVE-2015-1869HIGH7.8The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demons...
CVE-2015-2326MEDIUM5.5The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a ...
CVE-2015-2325HIGH7.8The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a de...
CVE-2015-0558MEDIUM5.3The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other ro...
CVE-2015-8367CRITICAL9.8The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbi...
CVE-2015-8366CRITICAL9.8Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause me...
CVE-2015-5951CRITICAL9.9A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to ...
CVE-2015-4553HIGH8.8A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
CVE-2015-4039MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent...
CVE-2015-9540MEDIUM6.1Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
CVE-2015-5595MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack ...
CVE-2015-5593MEDIUM6.1The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attacker...
CVE-2015-5592MEDIUM6.1Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting...
CVE-2015-5591HIGH7.2SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
CVE-2015-5290HIGH7.5A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler.
CVE-2015-8313MEDIUM5.9GnuTLS incorrectly validates the first byte of padding in CBC modes
CVE-2015-7892HIGH7.8Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in...
CVE-2015-3425MEDIUM6.1Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows...
CVE-2015-3424HIGH8.8SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote a...
CVE-2015-1853MEDIUM6.5chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows...
CVE-2015-0841HIGH7.5Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attac...
CVE-2015-7542MEDIUM5.3A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
CVE-2015-0837MEDIUM5.9The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now