2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-2046Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20.
CVE-2015-1876Directory traversal vulnerability in ES File Explorer 3.2.4.1.
CVE-2015-1445HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
CVE-2015-1443The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.
CVE-2015-1430Buffer overflow in xymon 4.3.17-1.
CVE-2015-1401Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
CVE-2015-1386Directory traversal vulnerability in unshield 1.0-1.
CVE-2015-1199Directory traversal vulnerability in ppmd 10.1-5.
CVE-2015-1198Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5.
CVE-2015-1177Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
CVE-2015-0974Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying th...
CVE-2015-0210wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-...
CVE-2015-0114Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.
CVE-2015-0101Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, ...
CVE-2015-5701mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files...
CVE-2015-5700mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via...
CVE-2015-4181Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbi...
CVE-2015-4180Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbi...
CVE-2015-4017Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
CVE-2015-3257Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote...
CVE-2015-3211php-fpm allows local users to write to or create arbitrary files via a symlink attack.
CVE-2015-3206The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allow...
CVE-2015-1395Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote atta...
CVE-2015-1325Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ub...
CVE-2015-1324Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now