2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-5601edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles ....
CVE-2015-9289MEDIUM5.5In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends...
CVE-2015-7882HIGH8.1Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to g...
CVE-2015-3907CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
CVE-2015-7609Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbr...
CVE-2015-2230MEDIUM6.1Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.
CVE-2015-9287Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification fiel...
CVE-2015-1006A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9....
CVE-2015-9286Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
CVE-2015-9285esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.
CVE-2015-9284HIGH8.8The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as ...
CVE-2015-1343LOW2All versions of unity-scope-gdrive logs search terms to syslog.
CVE-2015-1341HIGH7.4Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and t...
CVE-2015-1340HIGH7LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the...
CVE-2015-1327LOW3.9Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn...
CVE-2015-1326MEDIUM5.7python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method cou...
CVE-2015-1320MEDIUM5.5The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface...
CVE-2015-1316MEDIUM6.4Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
CVE-2015-5462AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dash...
CVE-2015-5384AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier is vulnerable to a Session Fixation attack.
CVE-2015-5463AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and ea...
CVE-2015-5606Vordel XML Gateway (acquired by Axway) version 7.2.2 could allow remote attackers to cause a denial of service via a spe...
CVE-2015-1014A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory...
CVE-2015-1012Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, v...
CVE-2015-1007A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now