2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1880Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote a...
CVE-2015-1860Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allo...
CVE-2015-1859Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x be...
CVE-2015-1858Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allo...
CVE-2015-3294The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function...
CVE-2015-3013ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the fi...
CVE-2015-3012Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers ...
CVE-2015-3011Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition bef...
CVE-2015-2347Cross-site scripting (XSS) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote attackers to...
CVE-2015-1907The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4 before 8.1.4.7 allows remote authe...
CVE-2015-1156The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6,...
CVE-2015-1155The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allo...
CVE-2015-1154WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute...
CVE-2015-1153WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute...
CVE-2015-1152WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute...
CVE-2015-3610The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from...
CVE-2015-0716Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 1...
CVE-2015-0715SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225...
CVE-2015-0701Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP reque...
CVE-2015-0538ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands ...
CVE-2015-0531EMC SourceOne Email Management before 7.2 does not have a lockout mechanism for invalid login attempts, which makes it e...
CVE-2015-0714Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow...
CVE-2015-3633Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory...
CVE-2015-3632Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory...
CVE-2015-3446The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now