2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-5536Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arb...
CVE-2015-5535Cross-site scripting (XSS) vulnerability in the qTranslate plugin 2.5.39 and earlier for WordPress allows remote attacke...
CVE-2015-5474BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a cr...
CVE-2015-4666Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attack...
CVE-2015-4665Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers ...
CVE-2015-3253The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to ex...
CVE-2015-2321Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack...
CVE-2015-5718Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0...
CVE-2015-5166Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which a...
CVE-2015-5165The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows...
CVE-2015-5154Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDRO...
CVE-2015-3908Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or...
CVE-2015-3287Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6587. Reason: This candidate is a duplicate of...
CVE-2015-3286Buffer overflow in the Solaris kernel extension in OpenAFS before 1.6.13 allows local users to cause a denial of service...
CVE-2015-3285The pioctl for the OSD FS command in OpenAFS before 1.6.13 uses the wrong pointer when writing the results of the RPC, w...
CVE-2015-3284pioctls in OpenAFS 1.6.x before 1.6.13 allows local users to read kernel memory via crafted commands.
CVE-2015-3283OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.
CVE-2015-3282vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the n...
CVE-2015-3213The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via c...
CVE-2015-3187The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based ...
CVE-2015-3184mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not ...
CVE-2015-2059The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to re...
CVE-2015-2058c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which a...
CVE-2015-1867Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges v...
CVE-2015-1334attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now