2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8572 | — | — | 3.8% | Dec 15, 2015 | Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitra... |
| CVE-2015-8571 | — | — | 3.4% | Dec 15, 2015 | Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code ... |
| CVE-2015-8570 | — | — | 1.2% | Dec 15, 2015 | The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arb... |
| CVE-2015-8377 | — | — | 1.7% | Dec 15, 2015 | SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows re... |
| CVE-2015-8317 | — | — | 5.7% | Dec 15, 2015 | The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive ... |
| CVE-2015-8247 | — | — | 1.9% | Dec 15, 2015 | Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remo... |
| CVE-2015-8242 | — | — | 4.3% | Dec 15, 2015 | The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-d... |
| CVE-2015-8241 | — | — | 6.7% | Dec 15, 2015 | The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to... |
| CVE-2015-7500 | — | — | 5.8% | Dec 15, 2015 | The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of se... |
| CVE-2015-7499 | — | — | 6.3% | Dec 15, 2015 | Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attacker... |
| CVE-2015-7498 | — | — | 7.0% | Dec 15, 2015 | Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent ... |
| CVE-2015-7497 | — | — | 7.0% | Dec 15, 2015 | Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-depen... |
| CVE-2015-5312 | — | — | 4.5% | Dec 15, 2015 | The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, ... |
| CVE-2015-5280 | — | — | — | Dec 15, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-8561 | — | — | 3.8% | Dec 15, 2015 | The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execu... |
| CVE-2015-7918 | — | — | 5.7% | Dec 15, 2015 | Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 all... |
| CVE-2015-6411 | — | — | 1.2% | Dec 15, 2015 | Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which... |
| CVE-2015-6404 | — | — | 1.0% | Dec 15, 2015 | Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to o... |
| CVE-2015-6403 | — | — | 0.4% | Dec 15, 2015 | The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image ... |
| CVE-2015-6399 | — | — | 2.2% | Dec 15, 2015 | The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authentic... |
| CVE-2015-6359 | — | — | 0.9% | Dec 15, 2015 | The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles... |
| CVE-2015-5004 | — | — | 1.1% | Dec 15, 2015 | The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 do... |
| CVE-2015-4206 | — | — | 1.9% | Dec 15, 2015 | Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism... |
| CVE-2015-8548 | — | — | 1.2% | Dec 14, 2015 | Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow ... |
| CVE-2015-6791 | — | — | 1.6% | Dec 14, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.80 allow attackers to cause a denial of service o... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now