2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-7723——AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
CVE-2015-7514——OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obt...
CVE-2015-7326——XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
CVE-2015-3830——The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows r...
CVE-2015-1207——Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a...
CVE-2015-9007——In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exis...
CVE-2015-9006——In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vuln...
CVE-2015-9005——In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerabili...
CVE-2015-6531——Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Pyth...
CVE-2015-5473——Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary...
CVE-2015-9059——picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line...
CVE-2015-0269——Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end"...
CVE-2015-8477——Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script ...
CVE-2015-8089——The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 be...
CVE-2015-6817——PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user ...
CVE-2015-6586——The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote att...
CVE-2015-5682——upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via...
CVE-2015-5609——Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and d...
CVE-2015-5469——Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers t...
CVE-2015-5468——Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attack...
CVE-2015-5401——Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.0...
CVE-2015-5383——Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1)...
CVE-2015-5382——program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated...
CVE-2015-5381——Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows re...
CVE-2015-4704——Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to re...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now