2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-1783The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd all...
CVE-2015-7894The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow...
CVE-2015-6816ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
CVE-2015-6498Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as ...
CVE-2015-3277The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of mu...
CVE-2015-2687OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes tha...
CVE-2015-2674Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Pyt...
CVE-2015-2313Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an ob...
CVE-2015-2312Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and ...
CVE-2015-2311Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a d...
CVE-2015-1820REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtai...
CVE-2015-0786Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration ...
CVE-2015-0785com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remot...
CVE-2015-0784Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged i...
CVE-2015-0783The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitra...
CVE-2015-0782SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Managemen...
CVE-2015-0781Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (...
CVE-2015-0780SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration...
CVE-2015-6941win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak passwo...
CVE-2015-5619Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SS...
CVE-2015-4165The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files ...
CVE-2015-3405ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy ...
CVE-2015-7571Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin...
CVE-2015-5946Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uplo...
CVE-2015-5244The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass applicati...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now