2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8264——Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and con...
CVE-2015-7891——Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A...
CVE-2015-5203——Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a d...
CVE-2015-3642——The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gatewa...
CVE-2015-2690——Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumadd...
CVE-2015-2560——Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Adminis...
CVE-2015-1174——Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote at...
CVE-2015-0839——The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execut...
CVE-2015-0194——XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and...
CVE-2015-5059——The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc...
CVE-2015-5191——VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths...
CVE-2015-8013——s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote a...
CVE-2015-6585——hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by l...
CVE-2015-5594——The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, w...
CVE-2015-5221——Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library...
CVE-2015-5187——Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of ...
CVE-2015-4463——The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-uploa...
CVE-2015-4462——Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenti...
CVE-2015-4035——scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons,...
CVE-2015-3278——The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers ...
CVE-2015-3243——rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by read...
CVE-2015-3208——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-3171MEDIUM5.5sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ ...
CVE-2015-3149——The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitra...
CVE-2015-2798——SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary S...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now