2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-7029Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attacker...
CVE-2015-6931Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U...
CVE-2015-8801Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass inte...
CVE-2015-8899Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address tha...
CVE-2015-8699Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 be...
CVE-2015-8698CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5...
CVE-2015-7473runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restri...
CVE-2015-7988The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary cod...
CVE-2015-7987Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memo...
CVE-2015-6289Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a deni...
CVE-2015-8289The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 a...
CVE-2015-8288NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded...
CVE-2015-7776Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for rem...
CVE-2015-7462IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords with...
CVE-2015-7775Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary we...
CVE-2015-8914The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an int...
CVE-2015-8869OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow a...
CVE-2015-8268The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary ...
CVE-2015-1797Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2015-7695The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attacke...
CVE-2015-7611Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst...
CVE-2015-5723Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1...
CVE-2015-5261Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations ...
CVE-2015-5260Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory ...
CVE-2015-5231The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obta...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now