2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8842——tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows...
CVE-2015-7802——gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitializ...
CVE-2015-7801——Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.
CVE-2015-8779——Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context...
CVE-2015-8778——Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a den...
CVE-2015-8776——The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause ...
CVE-2015-7511——Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it e...
CVE-2015-1776——Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key ...
CVE-2015-5479——The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denia...
CVE-2015-8106——Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers t...
CVE-2015-7552——Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote atta...
CVE-2015-5271——The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the Ope...
CVE-2015-7676——Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows r...
CVE-2015-5348——Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) cam...
CVE-2015-8677——Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V20...
CVE-2015-8676——Memory leak in Huawei S5300EI, S5300SI, S5310HI, S6300EI/ S2350EI, and S5300LI Campus series switches with software V200...
CVE-2015-5247——The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write conn...
CVE-2015-8560——Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters...
CVE-2015-8554——Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model,...
CVE-2015-8550——Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (hos...
CVE-2015-8540——Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1....
CVE-2015-7999——Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 3...
CVE-2015-5343——Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows...
CVE-2015-0284——Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenti...
CVE-2015-8683——The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now