2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-4035——scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons,...
CVE-2015-3278——The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers ...
CVE-2015-3243——rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by read...
CVE-2015-3208——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-3149——The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitra...
CVE-2015-2798——SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary S...
CVE-2015-1438——Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary ...
CVE-2015-1417——The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x ...
CVE-2015-1332——The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows...
CVE-2015-0904——The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote att...
CVE-2015-0674——Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote at...
CVE-2015-8009——The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4,...
CVE-2015-7543——aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hi...
CVE-2015-2280——snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709...
CVE-2015-2279——cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows...
CVE-2015-1847——Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attacker...
CVE-2015-5300——The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greate...
CVE-2015-5195——ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault)...
CVE-2015-5194——The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial...
CVE-2015-4639——Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16....
CVE-2015-3932——Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed d...
CVE-2015-3931——Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed...
CVE-2015-3886——libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified...
CVE-2015-3640——phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote aut...
CVE-2015-3639——phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to exec...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now