2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-7193——Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm f...
CVE-2015-7192——The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of t...
CVE-2015-7191——Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cr...
CVE-2015-7190——The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through...
CVE-2015-7189——Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote...
CVE-2015-7188——Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for...
CVE-2015-7187——The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for r...
CVE-2015-7186——Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigge...
CVE-2015-7185——Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which...
CVE-2015-7183——Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security...
CVE-2015-7182——Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x be...
CVE-2015-7181——The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, a...
CVE-2015-4518——The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remot...
CVE-2015-4515——Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitiv...
CVE-2015-4514——Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remote attackers to caus...
CVE-2015-4513——Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38...
CVE-2015-7650——Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015....
CVE-2015-7253——The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted seri...
CVE-2015-7244——The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently d...
CVE-2015-6867——The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to...
CVE-2015-6356——Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inj...
CVE-2015-6355——The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain po...
CVE-2015-6030——HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use...
CVE-2015-6029——HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier fo...
CVE-2015-5673——eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper p...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now