2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8868——Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remo...
CVE-2015-8863——Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (cras...
CVE-2015-0858——Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardif...
CVE-2015-0857——Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1...
CVE-2015-8830——Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause...
CVE-2015-8746——fs/nfs/nfs4proc.c in the NFS client in the Linux kernel before 4.2.2 does not properly initialize memory for migration r...
CVE-2015-8324——The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data str...
CVE-2015-8019——The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not ac...
CVE-2015-4178——The fs_pin implementation in the Linux kernel before 4.0.5 does not ensure the internal consistency of a certain list da...
CVE-2015-4177——The collect_mounts function in fs/namespace.c in the Linux kernel before 4.0.5 does not properly consider that it may ex...
CVE-2015-4176——fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users t...
CVE-2015-4170——Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-2013121...
CVE-2015-2686——net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom...
CVE-2015-2672——The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altin...
CVE-2015-1573——The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interacti...
CVE-2015-8845——The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms do...
CVE-2015-8844——The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the ...
CVE-2015-1339——Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to ...
CVE-2015-3572——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3572. Reason: This candidate is a duplicate of...
CVE-2015-3571——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3571. Reason: This candidate is a duplicate of...
CVE-2015-3569——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3569. Reason: This candidate is a duplicate of...
CVE-2015-8852——Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP h...
CVE-2015-5370——Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC laye...
CVE-2015-4829——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0638. Reason: This candidate is a reservation ...
CVE-2015-6360——The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now