2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7222 | — | — | 4.3% | Dec 16, 2015 | Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and... |
| CVE-2015-7221 | — | — | 4.5% | Dec 16, 2015 | Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might all... |
| CVE-2015-7220 | — | — | 4.5% | Dec 16, 2015 | Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote a... |
| CVE-2015-7219 | — | — | 2.9% | Dec 16, 2015 | The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer u... |
| CVE-2015-7218 | — | — | 2.9% | Dec 16, 2015 | The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer u... |
| CVE-2015-7217 | — | — | 2.8% | Dec 16, 2015 | The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder... |
| CVE-2015-7216 | — | — | 2.1% | Dec 16, 2015 | The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer deco... |
| CVE-2015-7215 | — | — | 2.5% | Dec 16, 2015 | The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers ... |
| CVE-2015-7214 | — | — | 6.1% | Dec 16, 2015 | Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via... |
| CVE-2015-7213 | — | — | 4.1% | Dec 16, 2015 | Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox... |
| CVE-2015-7212 | — | — | 4.0% | Dec 16, 2015 | Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0... |
| CVE-2015-7211 | — | — | 2.5% | Dec 16, 2015 | Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to sp... |
| CVE-2015-7210 | — | — | 4.3% | Dec 16, 2015 | Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to ... |
| CVE-2015-7208 | — | — | 2.4% | Dec 16, 2015 | Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain s... |
| CVE-2015-7207 | — | — | 2.8% | Dec 16, 2015 | Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allow... |
| CVE-2015-7205 | — | — | 3.2% | Dec 16, 2015 | Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x b... |
| CVE-2015-7204 | — | — | 3.5% | Dec 16, 2015 | Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to ... |
| CVE-2015-7203 | — | — | 4.3% | Dec 16, 2015 | Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla F... |
| CVE-2015-7202 | — | — | 5.9% | Dec 16, 2015 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to caus... |
| CVE-2015-7201 | — | — | 6.0% | Dec 16, 2015 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38... |
| CVE-2015-8572 | — | — | 3.8% | Dec 15, 2015 | Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitra... |
| CVE-2015-8571 | — | — | 3.4% | Dec 15, 2015 | Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code ... |
| CVE-2015-8570 | — | — | 1.2% | Dec 15, 2015 | The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arb... |
| CVE-2015-8377 | — | — | 1.7% | Dec 15, 2015 | SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows re... |
| CVE-2015-8317 | — | — | 5.7% | Dec 15, 2015 | The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now