2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-2688HIGH7.5buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffe...
CVE-2015-1530HIGH7.8media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_serve...
CVE-2015-4041HIGH7.8The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculati...
CVE-2015-5333HIGH7.5Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (m...
CVE-2015-1811HIGH7.5XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers...
CVE-2015-1809HIGH7.5XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers...
CVE-2015-6497HIGH8.8The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9....
CVE-2015-5230HIGH7.5The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote atta...
CVE-2015-5466HIGH7.8Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.10...
CVE-2015-8549HIGH7.1XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or re...
CVE-2015-7556HIGH7.8DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.
CVE-2015-3159HIGH7.8The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly ha...
CVE-2015-3151HIGH7.8Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write ...
CVE-2015-3150HIGH7.1abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files...
CVE-2015-1869HIGH7.8The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demons...
CVE-2015-2325HIGH7.8The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a de...
CVE-2015-4553HIGH8.8A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
CVE-2015-5591HIGH7.2SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
CVE-2015-5290HIGH7.5A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler.
CVE-2015-7892HIGH7.8Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in...
CVE-2015-3424HIGH8.8SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote a...
CVE-2015-0841HIGH7.5Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attac...
CVE-2015-3406HIGH7.5The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SI...
CVE-2015-7831HIGH8.8In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
CVE-2015-6495HIGH7.5There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now