2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-7568SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the a...
CVE-2015-7247D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and...
CVE-2015-7246D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou...
CVE-2015-7245Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot...
CVE-2015-8110Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by nav...
CVE-2015-8109Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by mak...
CVE-2015-1522analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which all...
CVE-2015-1521analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows...
CVE-2015-0107IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database ...
CVE-2015-0104IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database ...
CVE-2015-8285The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
CVE-2015-8959MEDIUM6.5coders/dds.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (CPU consumption) v...
CVE-2015-8958coders/sun.c in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (out-of-bounds read...
CVE-2015-8957Buffer overflow in ImageMagick before 6.9.0-4 Beta allows remote attackers to cause a denial of service (application cra...
CVE-2015-8256Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
CVE-2015-6568Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/...
CVE-2015-6567Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/...
CVE-2015-8356Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated u...
CVE-2015-8619HIGH7.5The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write an...
CVE-2015-8567HIGH7.7Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
CVE-2015-8345MEDIUM6.5The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash an...
CVE-2015-4646HIGH7.5(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attack...
CVE-2015-2947KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound ne...
CVE-2015-8780Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.
CVE-2015-8864Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attacker...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now