2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-3442Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API c...
CVE-2015-3250Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
CVE-2015-8316Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled a...
CVE-2015-7294HIGH7.5ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.
CVE-2015-7241XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
CVE-2015-7225Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successful...
CVE-2015-6250simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically gener...
CVE-2015-5959Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database passwor...
CVE-2015-5948Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exi...
CVE-2015-5947HIGH8.1SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
CVE-2015-5705Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a c...
CVE-2015-5186Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
CVE-2015-3454TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to o...
CVE-2015-3450Heap-based buffer overflow in libaxl 0.6.9 allows attackers to cause a denial of service (memory corruption) or execute ...
CVE-2015-3163MEDIUM4.3The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote...
CVE-2015-3162Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remot...
CVE-2015-3161The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals whe...
CVE-2015-3160XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to...
CVE-2015-2943Honda Moto LINC 1.6.1 does not verify SSL certificates.
CVE-2015-2210The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injectin...
CVE-2015-0853HIGH8.8svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by usi...
CVE-2015-7746NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtai...
CVE-2015-7711Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject ar...
CVE-2015-7700Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspe...
CVE-2015-5958HIGH8.8phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now