2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1427CRITICAL9.8The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s...
CVE-2015-0247Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execut...
CVE-2015-1613RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) ...
CVE-2015-1501The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (S...
CVE-2015-1500Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (S...
CVE-2015-1499The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and...
CVE-2015-1498Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote att...
CVE-2015-1497radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu...
CVE-2015-1496Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerSer...
CVE-2015-1495Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a cra...
CVE-2015-1436Cross-site scripting (XSS) vulnerability in the Easing Slider plugin before 2.2.0.7 for WordPress allows remote attacker...
CVE-2015-1435Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web...
CVE-2015-1434Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary ...
CVE-2015-0268The vgic_v2_to_sgi function in arch/arm/vgic-v2.c in Xen 4.5.x, when running on ARM hardware with general interrupt cont...
CVE-2015-0260RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive inform...
CVE-2015-1608Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection s...
CVE-2015-1474Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer....
CVE-2015-0609Race condition in the Common Classification Engine (CCE) in the Measurement, Aggregation, and Correlation Engine (MACE) ...
CVE-2015-1574The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent app...
CVE-2015-0875The Ogaki Kyoritsu Bank Smartphone Passbook application 1.0.0 for Android creates a log file containing input data from ...
CVE-2015-0519The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 p...
CVE-2015-0518The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P2...
CVE-2015-0517The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5...
CVE-2015-0931Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used,...
CVE-2015-0923The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now