2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4607 | — | — | 2.3% | Jun 16, 2015 | Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allo... |
| CVE-2015-4606 | — | — | 2.7% | Jun 16, 2015 | Unrestricted file upload vulnerability in the Job Fair (jobfair) extension before 1.0.1 for TYPO3, when using Apache wit... |
| CVE-2015-3395 | — | — | 2.4% | Jun 16, 2015 | The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x be... |
| CVE-2015-3205 | — | — | 10.7% | Jun 16, 2015 | libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, ... |
| CVE-2015-3010 | — | — | 0.4% | Jun 16, 2015 | ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to ob... |
| CVE-2015-2805 | — | — | 3.0% | Jun 16, 2015 | Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web int... |
| CVE-2015-2804 | — | — | 2.0% | Jun 16, 2015 | The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before ... |
| CVE-2015-4559 | — | — | 1.8% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee... |
| CVE-2015-4164 | — | — | 0.4% | Jun 15, 2015 | The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV gues... |
| CVE-2015-4163 | — | — | 0.4% | Jun 15, 2015 | GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local gues... |
| CVE-2015-4152 | — | — | 3.0% | Jun 15, 2015 | Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attacke... |
| CVE-2015-4146 | — | — | 3.5% | Jun 15, 2015 | The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More)... |
| CVE-2015-4145 | — | — | 3.4% | Jun 15, 2015 | The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is... |
| CVE-2015-4144 | — | — | 3.4% | Jun 15, 2015 | The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a messag... |
| CVE-2015-4143 | — | — | 3.5% | Jun 15, 2015 | The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to caus... |
| CVE-2015-4142 | — | — | 4.2% | Jun 15, 2015 | Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when... |
| CVE-2015-4141 | — | — | 3.0% | Jun 15, 2015 | The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 t... |
| CVE-2015-4119 | — | — | 1.3% | Jun 15, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijac... |
| CVE-2015-4118 | — | — | 2.1% | Jun 15, 2015 | SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated user... |
| CVE-2015-4093 | — | — | 2.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbi... |
| CVE-2015-3209 | — | — | 9.7% | Jun 15, 2015 | Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending ... |
| CVE-2015-4397 | — | — | 0.6% | Jun 15, 2015 | Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack... |
| CVE-2015-4396 | — | — | 0.6% | Jun 15, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Keyword Research module 6.x-1.x before 6.x-1.2 for Dru... |
| CVE-2015-4395 | — | — | 1.0% | Jun 15, 2015 | The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user f... |
| CVE-2015-4394 | — | — | 1.4% | Jun 15, 2015 | The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction an... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now