2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-7390SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the ...
CVE-2015-3248openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions for /var/lib/openhpi directory, which allows...
CVE-2015-5070The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp i...
CVE-2015-5069The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp i...
CVE-2015-0874Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers ...
CVE-2015-8707Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not ...
CVE-2015-0238selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege...
CVE-2015-8375Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
CVE-2015-8251OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3...
CVE-2015-7846Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows at...
CVE-2015-7785GANMA! App for iOS does not verify SSL certificates.
CVE-2015-7544redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote auth...
CVE-2015-7510Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
CVE-2015-7293Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef...
CVE-2015-6592Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell...
CVE-2015-5704scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
CVE-2015-5666ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.
CVE-2015-5327Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after.
CVE-2015-5263pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the serv...
CVE-2015-5184HIGH7.5Console: CORS headers set to allow all in Red Hat AMQ.
CVE-2015-5183HIGH7.5Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
CVE-2015-5182HIGH8.8Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
CVE-2015-5181The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
CVE-2015-5169Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
CVE-2015-7318Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now