2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-7723——AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
CVE-2015-7514——OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obt...
CVE-2015-7326——XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
CVE-2015-3830——The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows r...
CVE-2015-1207——Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a...
CVE-2015-9007——In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exis...
CVE-2015-9006——In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vuln...
CVE-2015-9005——In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerabili...
CVE-2015-6531——Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Pyth...
CVE-2015-5473——Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary...
CVE-2015-0936CRITICAL9.8Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot...
CVE-2015-9059——picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line...
CVE-2015-0269——Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end"...
CVE-2015-5211CRITICAL9.6Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versio...
CVE-2015-3191HIGH8.8With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo...
CVE-2015-3190MEDIUM6.1With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo...
CVE-2015-3189LOW3.7With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Clo...
CVE-2015-1834MEDIUM6.5A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release ve...
CVE-2015-8477——Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script ...
CVE-2015-8089——The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 be...
CVE-2015-6817——PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user ...
CVE-2015-6586——The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote att...
CVE-2015-5682——upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via...
CVE-2015-5609——Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and d...
CVE-2015-5469——Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers t...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now