2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8247 | — | — | 1.9% | Dec 15, 2015 | Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remo... |
| CVE-2015-8242 | — | — | 4.3% | Dec 15, 2015 | The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-d... |
| CVE-2015-8241 | — | — | 6.7% | Dec 15, 2015 | The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to... |
| CVE-2015-7500 | — | — | 5.8% | Dec 15, 2015 | The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of se... |
| CVE-2015-7499 | — | — | 6.3% | Dec 15, 2015 | Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attacker... |
| CVE-2015-7498 | — | — | 7.0% | Dec 15, 2015 | Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent ... |
| CVE-2015-7497 | — | — | 7.0% | Dec 15, 2015 | Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-depen... |
| CVE-2015-5312 | — | — | 4.5% | Dec 15, 2015 | The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, ... |
| CVE-2015-5280 | — | — | — | Dec 15, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-8561 | — | — | 3.8% | Dec 15, 2015 | The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execu... |
| CVE-2015-7918 | — | — | 5.7% | Dec 15, 2015 | Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 all... |
| CVE-2015-6420 | CRITICAL | 9.8 | 18.8% | Dec 15, 2015 | Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Netw... |
| CVE-2015-6411 | — | — | 1.2% | Dec 15, 2015 | Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which... |
| CVE-2015-6404 | — | — | 1.0% | Dec 15, 2015 | Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to o... |
| CVE-2015-6403 | — | — | 0.4% | Dec 15, 2015 | The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image ... |
| CVE-2015-6399 | — | — | 2.2% | Dec 15, 2015 | The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authentic... |
| CVE-2015-6359 | — | — | 0.9% | Dec 15, 2015 | The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles... |
| CVE-2015-5004 | — | — | 1.1% | Dec 15, 2015 | The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 do... |
| CVE-2015-4206 | — | — | 1.9% | Dec 15, 2015 | Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism... |
| CVE-2015-8548 | — | — | 1.2% | Dec 14, 2015 | Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow ... |
| CVE-2015-6791 | — | — | 1.6% | Dec 14, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.80 allow attackers to cause a denial of service o... |
| CVE-2015-6790 | — | — | 1.4% | Dec 14, 2015 | The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serialize... |
| CVE-2015-6789 | — | — | 1.7% | Dec 14, 2015 | Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows rem... |
| CVE-2015-6788 | — | — | 3.2% | Dec 14, 2015 | The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the extensions subsystem i... |
| CVE-2015-6422 | — | — | 1.9% | Dec 14, 2015 | The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now