2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-7294HIGH7.5ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.
CVE-2015-5947HIGH8.1SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
CVE-2015-0853HIGH8.8svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by usi...
CVE-2015-5958HIGH8.8phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
CVE-2015-3655HIGH8.8Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before...
CVE-2015-0928HIGH7.5libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
CVE-2015-5258HIGH8.8Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
CVE-2015-3649HIGH7.8The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp contain...
CVE-2015-2291HIGH7.8(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all...
CVE-2015-7764HIGH7.5Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
CVE-2015-7854HIGH8.8Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows rem...
CVE-2015-7849HIGH8.8Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated us...
CVE-2015-7704HIGH7.5The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service v...
CVE-2015-7701HIGH7.5Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote atta...
CVE-2015-7692HIGH7.5The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a...
CVE-2015-7691HIGH7.5The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a...
CVE-2015-7703HIGH7.5The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configur...
CVE-2015-5219HIGH7.5The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value...
CVE-2015-5232HIGH8.1Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.
CVE-2015-3191HIGH8.8With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Clo...
CVE-2015-5436HIGH7.5A potential security vulnerability has been identified with HP Integrated Lights-Out 4 (iLO 4) firmware version 2.11 and...
CVE-2015-9004HIGH7.8kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privi...
CVE-2015-8619HIGH7.5The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write an...
CVE-2015-8567HIGH7.7Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
CVE-2015-4646HIGH7.5(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attack...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now