2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-3200mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authenticati...
CVE-2015-4418Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which ma...
CVE-2015-2961Cross-site request forgery (CSRF) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers...
CVE-2015-2960Cross-site scripting (XSS) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to inj...
CVE-2015-2959Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attac...
CVE-2015-4053The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, ...
CVE-2015-4051Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attac...
CVE-2015-3905Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a den...
CVE-2015-3201Thermostat before 2.0.0 uses world-readable permissions for the web.xml configuration file, which allows local users to ...
CVE-2015-3001SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which al...
CVE-2015-3000SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a lar...
CVE-2015-2999Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary ...
CVE-2015-2998SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi...
CVE-2015-2997SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the account...
CVE-2015-2996Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar...
CVE-2015-2995The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at...
CVE-2015-2994Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t...
CVE-2015-2993SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t...
CVE-2015-4004The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which all...
CVE-2015-4003The oz_usb_handle_ep_data function in drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel throug...
CVE-2015-4002drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain l...
CVE-2015-4001Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in t...
CVE-2015-0779Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11...
CVE-2015-2125Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to by...
CVE-2015-0770CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now