2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-9096Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM comm...
CVE-2015-3913The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot...
CVE-2015-3634The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for W...
CVE-2015-2692AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary ...
CVE-2015-1786Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or ...
CVE-2015-1588Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-r...
CVE-2015-1379The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of serv...
CVE-2015-2800The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH...
CVE-2015-2255Huawei AR1220 routers with software before V200R005SPH006 allow remote attackers to cause a denial of service (board res...
CVE-2015-2253The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated use...
CVE-2015-2252Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary co...
CVE-2015-2251The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to...
CVE-2015-7346SQL injection vulnerability in ZCMS 1.1.
CVE-2015-3295markdown-it before 4.1.0 does not block data: URLs.
CVE-2015-8538MEDIUM6.5dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).
CVE-2015-8235Directory traversal vulnerability in Spiffy before 5.4.
CVE-2015-6959Cross-site scripting (XSS) vulnerability in Vindula 1.9.
CVE-2015-6540Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
CVE-2015-6240The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environme...
CVE-2015-5232HIGH8.1Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.
CVE-2015-5202Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-5233. Reason: This candidate is a reservation du...
CVE-2015-5175Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of ...
CVE-2015-8326The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
CVE-2015-7888Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remot...
CVE-2015-7724AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exist...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now