2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-4527Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1...
CVE-2015-4285The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k device...
CVE-2015-5605The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mishandles interrupts,...
CVE-2015-1289Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service o...
CVE-2015-1288The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a H...
CVE-2015-1287Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Ca...
CVE-2015-1286Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/...
CVE-2015-1285The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google ...
CVE-2015-1284The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.8...
CVE-2015-1283Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.24...
CVE-2015-1282Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome befor...
CVE-2015-1281core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 c...
CVE-2015-1280SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of ...
CVE-2015-1279Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chro...
CVE-2015-1278content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF docume...
CVE-2015-1277Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote atta...
CVE-2015-1276Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation i...
CVE-2015-1275Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2...
CVE-2015-1274Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it...
CVE-2015-1273Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, al...
CVE-2015-1272Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attack...
CVE-2015-1271PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which a...
CVE-2015-1270The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Go...
CVE-2015-4284The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to ...
CVE-2015-4281Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now