2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-0863GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in...
CVE-2015-8310Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbit...
CVE-2015-8309Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file...
CVE-2015-8678The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, ...
CVE-2015-8556Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
CVE-2015-8687Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manag...
CVE-2015-8628The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUpl...
CVE-2015-8627MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize...
CVE-2015-8626The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x be...
CVE-2015-8625MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize ...
CVE-2015-8624The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before ...
CVE-2015-8623The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not per...
CVE-2015-8622Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1....
CVE-2015-5729The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers gen...
CVE-2015-4166Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecif...
CVE-2015-4078Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, w...
CVE-2015-2263Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global rea...
CVE-2015-0855The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via s...
CVE-2015-8984The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to ca...
CVE-2015-8983Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2...
CVE-2015-8954The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might a...
CVE-2015-1610hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC...
CVE-2015-3883Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or...
CVE-2015-3882qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], w...
CVE-2015-3881Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now