2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-2877LOW3.3Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel...
CVE-2015-8994HIGH7.5An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache e...
CVE-2015-8903MEDIUM6.5The ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a ...
CVE-2015-8902MEDIUM6.5The ReadBlobByte function in coders/pdb.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a deni...
CVE-2015-8901MEDIUM6.5ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted M...
CVE-2015-8900MEDIUM5.5The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of servic...
CVE-2015-4057HIGH7.5The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon ...
CVE-2015-4056MEDIUM6.7The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which mak...
CVE-2015-8979Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows...
CVE-2015-8771The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands...
CVE-2015-8768click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allo...
CVE-2015-8750MEDIUM6.5libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) ...
CVE-2015-8936Cross-site scripting (XSS) vulnerability in squidGuard.cgi in squidGuard before 1.5 allows remote attackers to inject ar...
CVE-2015-8832Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authen...
CVE-2015-8831Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to injec...
CVE-2015-6024ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot...
CVE-2015-6023ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot...
CVE-2015-7494A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admi...
CVE-2015-7493IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during instal...
CVE-2015-7418IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory ins...
CVE-2015-1976IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool tha...
CVE-2015-5013MEDIUM5.5The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which...
CVE-2015-8544NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive i...
CVE-2015-8322NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspe...
CVE-2015-7599Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now