2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5688 | — | — | 9.4% | Sep 4, 2015 | Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read... |
| CVE-2015-5612 | — | — | 1.8% | Sep 4, 2015 | Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrar... |
| CVE-2015-6259 | — | — | 2.8% | Sep 4, 2015 | The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS D... |
| CVE-2015-4544 | — | — | 2.6% | Sep 4, 2015 | EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job ob... |
| CVE-2015-4538 | — | — | 2.7% | Sep 4, 2015 | The XML parser in EMC Atmos before 2.2.3.426 and 2.3.x before 2.3.1.0 allows remote authenticated users to read arbitrar... |
| CVE-2015-6583 | — | — | 1.4% | Sep 3, 2015 | Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from t... |
| CVE-2015-6582 | — | — | 0.9% | Sep 3, 2015 | The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.24... |
| CVE-2015-6581 | — | — | 2.7% | Sep 3, 2015 | Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as ... |
| CVE-2015-6580 | — | — | 0.6% | Sep 3, 2015 | Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before 45.0.2454.85, allow... |
| CVE-2015-1301 | — | — | 1.4% | Sep 3, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service o... |
| CVE-2015-1300 | — | — | 1.7% | Sep 3, 2015 | The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as us... |
| CVE-2015-1299 | — | — | 1.7% | Sep 3, 2015 | Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, ... |
| CVE-2015-1298 | — | — | 1.3% | Sep 3, 2015 | The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrom... |
| CVE-2015-1297 | — | — | 2.2% | Sep 3, 2015 | The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.... |
| CVE-2015-1296 | — | — | 1.5% | Sep 3, 2015 | The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not pr... |
| CVE-2015-1295 | — | — | 1.6% | Sep 3, 2015 | Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_h... |
| CVE-2015-1294 | — | — | 1.6% | Sep 3, 2015 | Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google... |
| CVE-2015-1293 | — | — | 1.5% | Sep 3, 2015 | The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Sam... |
| CVE-2015-1292 | — | — | 1.6% | Sep 3, 2015 | The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as use... |
| CVE-2015-1291 | — | — | 1.7% | Sep 3, 2015 | The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45... |
| CVE-2015-6545 | — | — | 2.6% | Sep 3, 2015 | Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the a... |
| CVE-2015-4552 | — | — | 1.9% | Sep 3, 2015 | Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before ... |
| CVE-2015-1516 | — | — | 0.8% | Sep 3, 2015 | Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticate... |
| CVE-2015-6654 | — | — | 0.4% | Sep 3, 2015 | The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of pr... |
| CVE-2015-6506 | — | — | 2.1% | Sep 3, 2015 | Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now