2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-4607Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allo...
CVE-2015-4606Unrestricted file upload vulnerability in the Job Fair (jobfair) extension before 1.0.1 for TYPO3, when using Apache wit...
CVE-2015-3395The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x be...
CVE-2015-3205libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, ...
CVE-2015-3010ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to ob...
CVE-2015-2805Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web int...
CVE-2015-2804The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before ...
CVE-2015-4559Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee...
CVE-2015-4164The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV gues...
CVE-2015-4163GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local gues...
CVE-2015-4152Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attacke...
CVE-2015-4146The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More)...
CVE-2015-4145The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is...
CVE-2015-4144The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a messag...
CVE-2015-4143The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to caus...
CVE-2015-4142Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when...
CVE-2015-4141The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 t...
CVE-2015-4119Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijac...
CVE-2015-4118SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated user...
CVE-2015-4093Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbi...
CVE-2015-3209Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending ...
CVE-2015-4397Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack...
CVE-2015-4396Multiple cross-site request forgery (CSRF) vulnerabilities in the Keyword Research module 6.x-1.x before 6.x-1.2 for Dru...
CVE-2015-4395The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user f...
CVE-2015-4394The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction an...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now