2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1303bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow acti...
CVE-2015-5659SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote ...
CVE-2015-5654Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web scri...
CVE-2015-5648SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitra...
CVE-2015-4929IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote au...
CVE-2015-7768Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma...
CVE-2015-7767Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of...
CVE-2015-7766PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q...
CVE-2015-7765ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a...
CVE-2015-5235IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows...
CVE-2015-5234IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to...
CVE-2015-1337Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirr...
CVE-2015-7761Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive...
CVE-2015-7760libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which ...
CVE-2015-5923Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically prox...
CVE-2015-5922Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.1...
CVE-2015-5919GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption...
CVE-2015-5918GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption...
CVE-2015-5917The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to c...
CVE-2015-5915Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified imp...
CVE-2015-5914The EFI component in Apple OS X before 10.11 allows physically proximate attackers to modify firmware during the EFI upd...
CVE-2015-5913Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server vi...
CVE-2015-5902The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a den...
CVE-2015-5901The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow lo...
CVE-2015-5900The protected range register in the EFI component in Apple OS X before 10.11 has an incorrect value, which allows attack...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now