2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-3638——phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary ...
CVE-2015-3421——The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables...
CVE-2015-3198——The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the ...
CVE-2015-3170——selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH logi...
CVE-2015-1323——The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0u...
CVE-2015-5152——Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to t...
CVE-2015-0249——The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for ...
CVE-2015-3297——Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to rea...
CVE-2015-9105——Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, ...
CVE-2015-9104——Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows ...
CVE-2015-9103——Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authentic...
CVE-2015-9102——Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-296...
CVE-2015-8697——stalin 0.11-5 allows local users to write to arbitrary files.
CVE-2015-7898——Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7895——Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7781——ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
CVE-2015-7780——Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
CVE-2015-7582——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-2100. Reason: This candidate is a reservation ...
CVE-2015-5378——Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwa...
CVE-2015-5180——res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereferen...
CVE-2015-3840——The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter se...
CVE-2015-2245——Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
CVE-2015-1795——Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
CVE-2015-1778——The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authe...
CVE-2015-1591——The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now