2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6790 | — | — | 1.4% | Dec 14, 2015 | The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serialize... |
| CVE-2015-6789 | — | — | 1.7% | Dec 14, 2015 | Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows rem... |
| CVE-2015-6788 | — | — | 3.2% | Dec 14, 2015 | The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the extensions subsystem i... |
| CVE-2015-6422 | — | — | 1.9% | Dec 14, 2015 | The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated ... |
| CVE-2015-6416 | — | — | 1.8% | Dec 14, 2015 | Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager ... |
| CVE-2015-6410 | — | — | 1.7% | Dec 14, 2015 | The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-devic... |
| CVE-2015-6402 | — | — | 7.5% | Dec 14, 2015 | Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, ... |
| CVE-2015-6401 | — | — | 8.0% | Dec 14, 2015 | Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication re... |
| CVE-2015-6378 | — | — | 0.8% | Dec 14, 2015 | Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hija... |
| CVE-2015-6418 | — | — | 1.8% | Dec 13, 2015 | The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have su... |
| CVE-2015-6414 | — | — | 0.2% | Dec 13, 2015 | Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' instal... |
| CVE-2015-6413 | — | — | 1.7% | Dec 13, 2015 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended... |
| CVE-2015-6407 | — | — | 1.6% | Dec 13, 2015 | Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted p... |
| CVE-2015-6406 | — | — | 2.3% | Dec 13, 2015 | Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authentic... |
| CVE-2015-6405 | — | — | 1.0% | Dec 13, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attacker... |
| CVE-2015-6400 | — | — | 0.9% | Dec 13, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inje... |
| CVE-2015-6389 | — | — | 2.6% | Dec 13, 2015 | Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain ... |
| CVE-2015-6361 | — | — | 1.4% | Dec 13, 2015 | The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated u... |
| CVE-2015-6419 | — | — | 1.1% | Dec 12, 2015 | Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users... |
| CVE-2015-6415 | — | — | 2.3% | Dec 12, 2015 | Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a den... |
| CVE-2015-6408 | — | — | 1.0% | Dec 12, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack t... |
| CVE-2015-6417 | — | — | 1.0% | Dec 12, 2015 | Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend data... |
| CVE-2015-6395 | — | — | 1.5% | Dec 12, 2015 | Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows ... |
| CVE-2015-7804 | — | — | 8.8% | Dec 11, 2015 | Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allow... |
| CVE-2015-7803 | — | — | 10.3% | Dec 11, 2015 | The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now