2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8139——ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecifie...
CVE-2015-8138——NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packe...
CVE-2015-7979——NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server associati...
CVE-2015-7978——NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via...
CVE-2015-7976——The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter...
CVE-2015-7975——The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, w...
CVE-2015-8862——mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by lever...
CVE-2015-8860——The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an ...
CVE-2015-8858——The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via craft...
CVE-2015-8855——The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long v...
CVE-2015-7743——XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to ...
CVE-2015-4626——B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the busine...
CVE-2015-8212——CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execut...
CVE-2015-8684——Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attack...
CVE-2015-8667——Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attack...
CVE-2015-3188——The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecifi...
CVE-2015-6501——Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect user...
CVE-2015-8020——Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions ...
CVE-2015-4594——eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a...
CVE-2015-4593——eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ...
CVE-2015-4592——eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow...
CVE-2015-4591——eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo...
CVE-2015-2868——An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS serv...
CVE-2015-2867——A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete co...
CVE-2015-3441——The Parental Control panel in Genexis devices with DRGOS before 1.14.1 allows remote authenticated users to execute arbi...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now