2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-2846BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
CVE-2015-2775Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers t...
CVE-2015-0840The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signat...
CVE-2015-0677The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 befor...
CVE-2015-0676The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8...
CVE-2015-0675The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(...
CVE-2015-0694Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint,...
CVE-2015-0692Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python...
CVE-2015-0678The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (...
CVE-2015-2247Unspecified vulnerability in Boosted Boards skateboards allows physically proximate attackers to modify skateboard movem...
CVE-2015-3027Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack st...
CVE-2015-3008Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified ...
CVE-2015-3005Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before ...
CVE-2015-3004J-Web in Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D35, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X...
CVE-2015-3003Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R9, 12...
CVE-2015-3002Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12....
CVE-2015-2806Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impa...
CVE-2015-2779Stack consumption vulnerability in the message splitting functionality in Quassel before 0.12-rc1 allows remote attacker...
CVE-2015-2778Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to caus...
CVE-2015-2295Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before...
CVE-2015-1842The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANG...
CVE-2015-1415The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable p...
CVE-2015-1149Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denia...
CVE-2015-1148Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-depen...
CVE-2015-1147Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances i...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now