2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-7507HIGH7.5libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a ...
CVE-2015-7505HIGH8.8Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attack...
CVE-2015-8751HIGH8.8Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impa...
CVE-2015-0258HIGH8.8Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before ...
CVE-2015-6589HIGH8.8Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before ...
CVE-2015-3309HIGH7.5Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to rea...
CVE-2015-7508HIGH8.8Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attac...
CVE-2015-3423HIGH8.8Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated us...
CVE-2015-2062HIGH7.2Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remo...
CVE-2015-6000HIGH8.8Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger...
CVE-2015-0102HIGH8.1IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier ...
CVE-2015-2802HIGH7.5An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Man...
CVE-2015-3611HIGH8.8A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspe...
CVE-2015-8851HIGH7.5node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to hav...
CVE-2015-0949HIGH7.8The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revis...
CVE-2015-5483HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote a...
CVE-2015-8012HIGH7.5lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malfo...
CVE-2015-0294HIGH7.5GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
CVE-2015-0243HIGH8.8Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3...
CVE-2015-0242HIGH8.8Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9....
CVE-2015-0241HIGH8.8The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4....
CVE-2015-9541HIGH7.5Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlS...
CVE-2015-2929HIGH7.5The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6....
CVE-2015-2928HIGH7.5The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6....
CVE-2015-2689HIGH7.5Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during period...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now