2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-2158Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers t...
CVE-2015-1206Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged mem...
CVE-2015-7980Cross-site scripting (XSS) vulnerability in the Compass Rose module 6.x-1.x before 6.x-1.1 for Drupal allows remote atta...
CVE-2015-7843The management interface on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V...
CVE-2015-7841The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH228...
CVE-2015-7359The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.1...
CVE-2015-7358The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run...
CVE-2015-7357Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows re...
CVE-2015-6971Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the...
CVE-2015-6576Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execut...
CVE-2015-3321Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalid...
CVE-2015-9234The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection vi...
CVE-2015-9233HIGH8.8The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with result...
CVE-2015-1027The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HT...
CVE-2015-8249The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e...
CVE-2015-7349Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Ci...
CVE-2015-7256ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A,...
CVE-2015-5613Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrar...
CVE-2015-3643usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubu...
CVE-2015-3138print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process ...
CVE-2015-1537Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code...
CVE-2015-1526The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.
CVE-2015-1336The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t...
CVE-2015-7670Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordP...
CVE-2015-7391Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now