2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7185 | — | — | 1.5% | Nov 5, 2015 | Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which... |
| CVE-2015-7183 | — | — | 6.8% | Nov 5, 2015 | Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security... |
| CVE-2015-7182 | — | — | 10.2% | Nov 5, 2015 | Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x be... |
| CVE-2015-7181 | — | — | 7.5% | Nov 5, 2015 | The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, a... |
| CVE-2015-4518 | — | — | 2.3% | Nov 5, 2015 | The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remot... |
| CVE-2015-4515 | — | — | 1.9% | Nov 5, 2015 | Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitiv... |
| CVE-2015-4514 | — | — | 4.5% | Nov 5, 2015 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remote attackers to caus... |
| CVE-2015-4513 | — | — | 4.2% | Nov 5, 2015 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38... |
| CVE-2015-7650 | — | — | 3.8% | Nov 4, 2015 | Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.... |
| CVE-2015-7253 | — | — | 4.3% | Nov 4, 2015 | The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted seri... |
| CVE-2015-7244 | — | — | 5.0% | Nov 4, 2015 | The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently d... |
| CVE-2015-6867 | — | — | 4.7% | Nov 4, 2015 | The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to... |
| CVE-2015-6356 | — | — | 1.4% | Nov 4, 2015 | Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inj... |
| CVE-2015-6355 | — | — | 1.7% | Nov 4, 2015 | The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain po... |
| CVE-2015-6030 | — | — | 0.6% | Nov 4, 2015 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use... |
| CVE-2015-6029 | — | — | 4.4% | Nov 4, 2015 | HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier fo... |
| CVE-2015-5673 | — | — | 2.5% | Nov 4, 2015 | eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper p... |
| CVE-2015-5021 | — | — | 2.3% | Nov 4, 2015 | IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execu... |
| CVE-2015-4927 | — | — | 0.4% | Nov 4, 2015 | The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 befor... |
| CVE-2015-2903 | — | — | 1.3% | Nov 4, 2015 | The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for ... |
| CVE-2015-2902 | — | — | 1.5% | Nov 4, 2015 | HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-m... |
| CVE-2015-8074 | — | — | 0.9% | Nov 3, 2015 | mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently byp... |
| CVE-2015-8073 | — | — | 2.2% | Nov 3, 2015 | mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a deni... |
| CVE-2015-8072 | — | — | 2.2% | Nov 3, 2015 | mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute ... |
| CVE-2015-6614 | — | — | 0.6% | Nov 3, 2015 | Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended netwo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now