2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6038 | — | — | 35.6% | Nov 11, 2015 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 ... |
| CVE-2015-2503 | — | — | 16.8% | Nov 11, 2015 | Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, P... |
| CVE-2015-2478 | — | — | 1.9% | Nov 11, 2015 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2... |
| CVE-2015-2427 | — | — | 13.3% | Nov 11, 2015 | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor... |
| CVE-2015-1302 | — | — | 1.9% | Nov 11, 2015 | The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, whic... |
| CVE-2015-8105 | — | — | 1.5% | Nov 10, 2015 | Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 a... |
| CVE-2015-8025 | — | — | 0.5% | Nov 10, 2015 | driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows phys... |
| CVE-2015-7994 | — | — | 3.4% | Nov 10, 2015 | The SQL interface in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via ... |
| CVE-2015-7993 | — | — | 3.7% | Nov 10, 2015 | The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote at... |
| CVE-2015-7992 | — | — | 1.6% | Nov 10, 2015 | SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to cause a denial of service (memory corr... |
| CVE-2015-7991 | — | — | 1.8% | Nov 10, 2015 | The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to read web dispatche... |
| CVE-2015-7828 | — | — | 6.5% | Nov 10, 2015 | SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitra... |
| CVE-2015-5214 | — | — | 9.6% | Nov 10, 2015 | LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a deni... |
| CVE-2015-5213 | — | — | 12.9% | Nov 10, 2015 | Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denia... |
| CVE-2015-5212 | — | — | 8.8% | Nov 10, 2015 | Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load p... |
| CVE-2015-4551 | — | — | 13.8% | Nov 10, 2015 | LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in ... |
| CVE-2015-8100 | — | — | 0.5% | Nov 10, 2015 | The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sen... |
| CVE-2015-6362 | — | — | 1.4% | Nov 10, 2015 | The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticat... |
| CVE-2015-5655 | — | — | 0.6% | Nov 10, 2015 | The Adways Party Track SDK before 1.6.6 for iOS does not verify X.509 certificates from SSL servers, which allows man-in... |
| CVE-2015-8007 | — | — | 1.6% | Nov 9, 2015 | The Echo extension for MediWiki does not properly implement the hideuser functionality, which allows remote authenticate... |
| CVE-2015-8006 | — | — | 1.2% | Nov 9, 2015 | Cross-site scripting (XSS) vulnerability in the PageTriage toolbar in the PageTriage extension for MediWiki allows remot... |
| CVE-2015-8005 | — | — | 1.4% | Nov 9, 2015 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line arg... |
| CVE-2015-8004 | — | — | 1.7% | Nov 9, 2015 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not properly restrict access to revisions,... |
| CVE-2015-8003 | — | — | 1.5% | Nov 9, 2015 | MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows re... |
| CVE-2015-8002 | — | — | 1.5% | Nov 9, 2015 | The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 allows re... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now