2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8757——Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allo...
CVE-2015-8756——Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in T...
CVE-2015-8755——Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7...
CVE-2015-8754——The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and ...
CVE-2015-8753——SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a craft...
CVE-2015-8615——The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages ...
CVE-2015-8612——The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users...
CVE-2015-8597——Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might ...
CVE-2015-8547——The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to ...
CVE-2015-8481——Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong ima...
CVE-2015-8303——Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closi...
CVE-2015-8226——The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL0...
CVE-2015-8225——The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL0...
CVE-2015-7758——Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the na...
CVE-2015-7754——Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of s...
CVE-2015-7554——The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory ...
CVE-2015-7519——agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache in...
CVE-2015-7362——Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable ...
CVE-2015-7328——Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permission...
CVE-2015-6856——Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locati...
CVE-2015-5259——Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows r...
CVE-2015-5254——Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remot...
CVE-2015-8261——The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized...
CVE-2015-6862——HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrict...
CVE-2015-6434——Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now