2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1323The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0u...
CVE-2015-5152Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to t...
CVE-2015-0249The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for ...
CVE-2015-3297Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to rea...
CVE-2015-9105Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, ...
CVE-2015-9104Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows ...
CVE-2015-9103Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authentic...
CVE-2015-9102Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-296...
CVE-2015-8697stalin 0.11-5 allows local users to write to arbitrary files.
CVE-2015-7898Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7895Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7781ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
CVE-2015-7780Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
CVE-2015-7582Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-2100. Reason: This candidate is a reservation ...
CVE-2015-5378Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwa...
CVE-2015-5180res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereferen...
CVE-2015-3840The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter se...
CVE-2015-2245Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
CVE-2015-1795Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
CVE-2015-1778The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authe...
CVE-2015-1591The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.
CVE-2015-0955Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0955. Reason: This candidate is a duplicate of...
CVE-2015-3315Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac...
CVE-2015-3215The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length...
CVE-2015-3142The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of fi...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now