2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1323——The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0u...
CVE-2015-5152——Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to t...
CVE-2015-0249——The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for ...
CVE-2015-3297——Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to rea...
CVE-2015-9105——Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, ...
CVE-2015-9104——Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows ...
CVE-2015-9103——Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authentic...
CVE-2015-9102——Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-296...
CVE-2015-8697——stalin 0.11-5 allows local users to write to arbitrary files.
CVE-2015-7898——Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7895——Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7781——ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
CVE-2015-7780——Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
CVE-2015-7582——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-2100. Reason: This candidate is a reservation ...
CVE-2015-5378——Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwa...
CVE-2015-5180——res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereferen...
CVE-2015-3840——The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter se...
CVE-2015-2245——Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
CVE-2015-1795——Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
CVE-2015-1778——The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authe...
CVE-2015-1591——The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.
CVE-2015-0955——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0955. Reason: This candidate is a duplicate of...
CVE-2015-3315——Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac...
CVE-2015-3215——The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length...
CVE-2015-3142——The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of fi...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now