2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1430——Buffer overflow in xymon 4.3.17-1.
CVE-2015-1401——Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
CVE-2015-1386——Directory traversal vulnerability in unshield 1.0-1.
CVE-2015-1199——Directory traversal vulnerability in ppmd 10.1-5.
CVE-2015-1198——Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5.
CVE-2015-1177——Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
CVE-2015-0974——Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying th...
CVE-2015-0928HIGH7.5libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
CVE-2015-0210——wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-...
CVE-2015-0114——Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.
CVE-2015-0101——Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, ...
CVE-2015-5701——mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files...
CVE-2015-5700——mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via...
CVE-2015-4181——Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbi...
CVE-2015-4180——Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbi...
CVE-2015-4017——Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
CVE-2015-3257——Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote...
CVE-2015-3211——php-fpm allows local users to write to or create arbitrary files via a symlink attack.
CVE-2015-3206——The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allow...
CVE-2015-1395——Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote atta...
CVE-2015-1325——Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ub...
CVE-2015-1324——Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before...
CVE-2015-8355——Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenti...
CVE-2015-8352——Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files...
CVE-2015-4699——Cross-site scripting (XSS) vulnerability in the Splash Portal in Cloud4Wi before 5.9.7 allows remote attackers to inject...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now