2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2015-8033MEDIUM5.3In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
CVE-2015-8032MEDIUM5.3In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
CVE-2015-9549MEDIUM6.1A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME ...
CVE-2015-7946MEDIUM4.6Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. ...
CVE-2015-9546MEDIUM4.8An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTT...
CVE-2015-7968MEDIUM4.3nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusio...
CVE-2015-7344MEDIUM4.8HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].
CVE-2015-7343MEDIUM4.8JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
CVE-2015-5361MEDIUM6.5Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open relate...
CVE-2015-3006MEDIUM6.5On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the de...
CVE-2015-2992MEDIUM6.1Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
CVE-2015-2923MEDIUM6.5The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to...
CVE-2015-0749MEDIUM6.1A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cro...
CVE-2015-7506MEDIUM6.5The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of servic...
CVE-2015-5216MEDIUM6.1The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python...
CVE-2015-5215MEDIUM6.1The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 bef...
CVE-2015-4715MEDIUM4.9The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x ...
CVE-2015-7890MEDIUM5.5Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung ...
CVE-2015-2207MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote aut...
CVE-2015-1394MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote...
CVE-2015-3612MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspec...
CVE-2015-7851MEDIUM6.5Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used ...
CVE-2015-2249MEDIUM5.4Zimbra Collaboration before 8.6.0 patch5 has XSS.
CVE-2015-3154MEDIUM6.1CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x befo...
CVE-2015-1525MEDIUM5.5audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy appli...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now