2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8140The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sniffing the network.
CVE-2015-8139ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecifie...
CVE-2015-8138NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packe...
CVE-2015-7979NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server associati...
CVE-2015-7978NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via...
CVE-2015-7976The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter...
CVE-2015-7975The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, w...
CVE-2015-8862mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by lever...
CVE-2015-8860The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an ...
CVE-2015-8858The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via craft...
CVE-2015-8855The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long v...
CVE-2015-7743XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to ...
CVE-2015-4626B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the busine...
CVE-2015-8212CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execut...
CVE-2015-8684Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attack...
CVE-2015-8667Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attack...
CVE-2015-3188The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecifi...
CVE-2015-6501Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect user...
CVE-2015-8020Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions ...
CVE-2015-4594eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a...
CVE-2015-4593eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ...
CVE-2015-4592eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow...
CVE-2015-4591eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo...
CVE-2015-2868An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS serv...
CVE-2015-2867A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete co...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now