2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-6931——Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U...
CVE-2015-8801——Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass inte...
CVE-2015-8899——Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address tha...
CVE-2015-8699——Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 be...
CVE-2015-8698——CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5...
CVE-2015-7473——runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restri...
CVE-2015-7988——The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary cod...
CVE-2015-7987——Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memo...
CVE-2015-6289——Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a deni...
CVE-2015-8289——The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 a...
CVE-2015-8288——NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded...
CVE-2015-7776——Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for rem...
CVE-2015-7462——IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords with...
CVE-2015-7775——Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary we...
CVE-2015-8914——The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an int...
CVE-2015-8869——OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow a...
CVE-2015-8268——The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary ...
CVE-2015-1797——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2015-7695——The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attacke...
CVE-2015-7611——Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst...
CVE-2015-5723——Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1...
CVE-2015-5261——Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations ...
CVE-2015-5260——Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory ...
CVE-2015-5231——The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obta...
CVE-2015-5228——The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now