2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8963HIGH7Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a d...
CVE-2015-8962HIGH7.3Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows loc...
CVE-2015-8961HIGH7.8The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain priv...
CVE-2015-8969CRITICAL9.8git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious...
CVE-2015-8968HIGH8.8git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a use...
CVE-2015-0787XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the ac...
CVE-2015-8953fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to...
CVE-2015-8952The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr bloc...
CVE-2015-3288HIGH7.8mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or ...
CVE-2015-8956The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain...
CVE-2015-8955HIGH7.3arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges o...
CVE-2015-8951Multiple use-after-free vulnerabilities in sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm sound driver in Androi...
CVE-2015-8950arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products...
CVE-2015-0572HIGH7Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux...
CVE-2015-7363Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5....
CVE-2015-5162The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12....
CVE-2015-2080The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive informat...
CVE-2015-1000013Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1
CVE-2015-1000012Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
CVE-2015-1000011Blind SQL Injection in wordpress plugin dukapress v2.5.9
CVE-2015-1000010Remote file download in simple-image-manipulator v1.0 wordpress plugin
CVE-2015-1000009Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
CVE-2015-1000008Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2
CVE-2015-1000007Remote file download vulnerability in wptf-image-gallery v1.03
CVE-2015-1000006Remote file download vulnerability in recent-backups v0.7 wordpress plugin

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now