2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-7894——The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow...
CVE-2015-6816——ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
CVE-2015-6498——Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as ...
CVE-2015-3277——The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of mu...
CVE-2015-2687——OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes tha...
CVE-2015-2674——Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Pyt...
CVE-2015-2313——Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an ob...
CVE-2015-2312——Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and ...
CVE-2015-2311——Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a d...
CVE-2015-1820——REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtai...
CVE-2015-0786——Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration ...
CVE-2015-0785——com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remot...
CVE-2015-0784——Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged i...
CVE-2015-0783——The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitra...
CVE-2015-0782——SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Managemen...
CVE-2015-0781——Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (...
CVE-2015-0780——SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration...
CVE-2015-6941——win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak passwo...
CVE-2015-5619——Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SS...
CVE-2015-4165——The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files ...
CVE-2015-3405——ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy ...
CVE-2015-7571——Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin...
CVE-2015-5946——Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uplo...
CVE-2015-5244——The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass applicati...
CVE-2015-8621——t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now