2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-6789——Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows rem...
CVE-2015-6788——The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the extensions subsystem i...
CVE-2015-6422——The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated ...
CVE-2015-6416——Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager ...
CVE-2015-6410——The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-devic...
CVE-2015-6402——Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, ...
CVE-2015-6401——Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication re...
CVE-2015-6378——Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hija...
CVE-2015-6418——The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have su...
CVE-2015-6414——Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' instal...
CVE-2015-6413——Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended...
CVE-2015-6407——Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted p...
CVE-2015-6406——Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authentic...
CVE-2015-6405——Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attacker...
CVE-2015-6400——Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inje...
CVE-2015-6389——Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain ...
CVE-2015-6361——The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated u...
CVE-2015-6419——Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users...
CVE-2015-6415——Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a den...
CVE-2015-6408——Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack t...
CVE-2015-6417——Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend data...
CVE-2015-6395——Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows ...
CVE-2015-7804——Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allow...
CVE-2015-7803——The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers...
CVE-2015-7113——The LaunchServices component in Apple iOS before 9.2 and watchOS before 2.1 allows attackers to execute arbitrary code i...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now