2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-3435Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an...
CVE-2015-3337Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, a...
CVE-2015-3153The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination...
CVE-2015-2248Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products...
CVE-2015-0257Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovi...
CVE-2015-0237Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during li...
CVE-2015-1250Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service ...
CVE-2015-1243Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM im...
CVE-2015-0914EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP r...
CVE-2015-0913Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web...
CVE-2015-0912EasyCTF before 1.4 allows remote authenticated users to write executable content to files via unspecified vectors.
CVE-2015-0712The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attac...
CVE-2015-0532EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password...
CVE-2015-3459The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root...
CVE-2015-3458The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterpri...
CVE-2015-3457Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authenticat...
CVE-2015-1399PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento ...
CVE-2015-1398Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14....
CVE-2015-1397SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit...
CVE-2015-3448REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sen...
CVE-2015-3447Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x al...
CVE-2015-3026Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a d...
CVE-2015-1322Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, ...
CVE-2015-1321Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a ...
CVE-2015-0711The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows r...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now