2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3335 | — | — | 1.9% | Apr 19, 2015 | The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Goo... |
| CVE-2015-3334 | — | — | 1.5% | Apr 19, 2015 | browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always display "Media: All... |
| CVE-2015-3333 | — | — | 0.9% | Apr 19, 2015 | Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow ... |
| CVE-2015-1249 | — | — | 1.4% | Apr 19, 2015 | Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service o... |
| CVE-2015-1248 | — | — | 1.5% | Apr 19, 2015 | The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executabl... |
| CVE-2015-1247 | — | — | 1.4% | Apr 19, 2015 | The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chr... |
| CVE-2015-1246 | — | — | 1.6% | Apr 19, 2015 | Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds... |
| CVE-2015-1245 | — | — | 1.8% | Apr 19, 2015 | Use-after-free vulnerability in the OpenPDFInReaderView::Update function in browser/ui/views/location_bar/open_pdf_in_re... |
| CVE-2015-1244 | — | — | 1.4% | Apr 19, 2015 | The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not rep... |
| CVE-2015-1242 | — | — | 2.7% | Apr 19, 2015 | The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Goog... |
| CVE-2015-1241 | — | — | 2.2% | Apr 19, 2015 | Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of tou... |
| CVE-2015-1240 | — | — | 1.2% | Apr 19, 2015 | gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote at... |
| CVE-2015-1238 | — | — | 1.6% | Apr 19, 2015 | Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds ... |
| CVE-2015-1237 | — | — | 1.7% | Apr 19, 2015 | Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc... |
| CVE-2015-1236 | — | — | 1.5% | Apr 19, 2015 | The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio A... |
| CVE-2015-1235 | — | — | 1.6% | Apr 19, 2015 | The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Goog... |
| CVE-2015-0970 | HIGH | 8.8 | 1.0% | Apr 18, 2015 | Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentic... |
| CVE-2015-0969 | — | — | 13.7% | Apr 18, 2015 | SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/h... |
| CVE-2015-0968 | — | — | 2.6% | Apr 18, 2015 | Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 8.2 allows remote attackers to exe... |
| CVE-2015-0967 | — | — | 1.3% | Apr 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in SearchBlox before 8.2 allow remote attackers to inject arbitrary ... |
| CVE-2015-1856 | — | — | 3.9% | Apr 17, 2015 | OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to de... |
| CVE-2015-1852 | — | — | 2.6% | Apr 17, 2015 | The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables cer... |
| CVE-2015-1318 | — | — | 4.1% | Apr 17, 2015 | The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf... |
| CVE-2015-0845 | — | — | 3.7% | Apr 17, 2015 | Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x befo... |
| CVE-2015-0938 | — | — | 1.5% | Apr 17, 2015 | search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attacke... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now