2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8923The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows...
CVE-2015-8922The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to...
CVE-2015-8921The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of s...
CVE-2015-8920The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to c...
CVE-2015-8919The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote...
CVE-2015-8918The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a den...
CVE-2015-8917bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and cra...
CVE-2015-8916bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in m...
CVE-2015-8915bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via cra...
CVE-2015-8948idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte...
CVE-2015-5721Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attack...
CVE-2015-5720Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Plat...
CVE-2015-5719app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly re...
CVE-2015-5399Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary we...
CVE-2015-8949Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified...
CVE-2015-8022The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3....
CVE-2015-6397Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remo...
CVE-2015-6396The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell command...
CVE-2015-3854packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypas...
CVE-2015-0573CRITICAL9.8drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Ce...
CVE-2015-0568HIGH7.8Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driv...
CVE-2015-8935The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 supports de...
CVE-2015-8944The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05...
CVE-2015-8943drivers/video/msm/mdss/mdss_mdp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does n...
CVE-2015-8942drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexu...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now