2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1430Buffer overflow in xymon 4.3.17-1.
CVE-2015-1401Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
CVE-2015-1386Directory traversal vulnerability in unshield 1.0-1.
CVE-2015-1199Directory traversal vulnerability in ppmd 10.1-5.
CVE-2015-1198Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5.
CVE-2015-1177Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
CVE-2015-0974Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying th...
CVE-2015-0928HIGH7.5libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
CVE-2015-0210wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-...
CVE-2015-0114Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.
CVE-2015-0101Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, ...
CVE-2015-5701mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files...
CVE-2015-5700mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via...
CVE-2015-4181Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbi...
CVE-2015-4180Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbi...
CVE-2015-4017Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
CVE-2015-3257Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote...
CVE-2015-3211php-fpm allows local users to write to or create arbitrary files via a symlink attack.
CVE-2015-3206The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allow...
CVE-2015-1395Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote atta...
CVE-2015-1325Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ub...
CVE-2015-1324Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before...
CVE-2015-8355Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenti...
CVE-2015-8352Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files...
CVE-2015-4699Cross-site scripting (XSS) vulnerability in the Splash Portal in Cloud4Wi before 5.9.7 allows remote attackers to inject...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now