2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8309Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file...
CVE-2015-8026HIGH7.8Heap-based buffer overflow in the verify_vbr_checksum function in exfatfsck in exfat-utils before 1.2.1 allows remote at...
CVE-2015-8678The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, ...
CVE-2015-8556Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
CVE-2015-8687Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manag...
CVE-2015-8628The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUpl...
CVE-2015-8627MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize...
CVE-2015-8626The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x be...
CVE-2015-8625MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize ...
CVE-2015-8624The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before ...
CVE-2015-8623The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not per...
CVE-2015-8622Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1....
CVE-2015-5729The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers gen...
CVE-2015-4166Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecif...
CVE-2015-4078Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, w...
CVE-2015-2263Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global rea...
CVE-2015-0855The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via s...
CVE-2015-8985MEDIUM5.9The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a deni...
CVE-2015-8984The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to ca...
CVE-2015-8983Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2...
CVE-2015-8954The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might a...
CVE-2015-1610hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC...
CVE-2015-7313MEDIUM5.5LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted t...
CVE-2015-4645MEDIUM5.5Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers...
CVE-2015-3884HIGH8.8Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now