2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8264Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and con...
CVE-2015-7891Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A...
CVE-2015-5203Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a d...
CVE-2015-3642The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gatewa...
CVE-2015-2690Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumadd...
CVE-2015-2560Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Adminis...
CVE-2015-1174Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote at...
CVE-2015-0839The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execut...
CVE-2015-0194XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and...
CVE-2015-5059The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc...
CVE-2015-5191VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths...
CVE-2015-8013s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote a...
CVE-2015-6585hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by l...
CVE-2015-5594The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, w...
CVE-2015-5221Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library...
CVE-2015-5187Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of ...
CVE-2015-4463The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-uploa...
CVE-2015-4462Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenti...
CVE-2015-4035scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons,...
CVE-2015-3278The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers ...
CVE-2015-3243rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by read...
CVE-2015-3208Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-3171MEDIUM5.5sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ ...
CVE-2015-3149The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitra...
CVE-2015-2798SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary S...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now