2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4527 | — | — | 2.7% | Jul 23, 2015 | Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1... |
| CVE-2015-4285 | — | — | 1.7% | Jul 23, 2015 | The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k device... |
| CVE-2015-5605 | — | — | 1.5% | Jul 23, 2015 | The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mishandles interrupts,... |
| CVE-2015-1289 | — | — | 1.3% | Jul 23, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service o... |
| CVE-2015-1288 | — | — | 1.1% | Jul 23, 2015 | The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a H... |
| CVE-2015-1287 | — | — | 1.5% | Jul 23, 2015 | Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Ca... |
| CVE-2015-1286 | — | — | 1.9% | Jul 23, 2015 | Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/... |
| CVE-2015-1285 | — | — | 1.4% | Jul 23, 2015 | The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google ... |
| CVE-2015-1284 | — | — | 2.2% | Jul 23, 2015 | The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.8... |
| CVE-2015-1283 | — | — | 19.1% | Jul 23, 2015 | Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.24... |
| CVE-2015-1282 | — | — | 1.6% | Jul 23, 2015 | Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome befor... |
| CVE-2015-1281 | — | — | 1.7% | Jul 23, 2015 | core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 c... |
| CVE-2015-1280 | — | — | 1.6% | Jul 23, 2015 | SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of ... |
| CVE-2015-1279 | — | — | 2.1% | Jul 23, 2015 | Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chro... |
| CVE-2015-1278 | — | — | 1.8% | Jul 23, 2015 | content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF docume... |
| CVE-2015-1277 | — | — | 1.6% | Jul 23, 2015 | Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote atta... |
| CVE-2015-1276 | — | — | 1.6% | Jul 23, 2015 | Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation i... |
| CVE-2015-1275 | — | — | 1.6% | Jul 23, 2015 | Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2... |
| CVE-2015-1274 | — | — | 3.6% | Jul 23, 2015 | Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it... |
| CVE-2015-1273 | — | — | 1.5% | Jul 23, 2015 | Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, al... |
| CVE-2015-1272 | — | — | 1.6% | Jul 23, 2015 | Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attack... |
| CVE-2015-1271 | — | — | 1.9% | Jul 23, 2015 | PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which a... |
| CVE-2015-1270 | — | — | 2.7% | Jul 23, 2015 | The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Go... |
| CVE-2015-4284 | — | — | 2.4% | Jul 22, 2015 | The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to ... |
| CVE-2015-4281 | — | — | 1.0% | Jul 22, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now