2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-2751Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control ...
CVE-2015-2294Multiple cross-site scripting (XSS) vulnerabilities in the WebGUI in pfSense before 2.2.1 allow remote attackers to inje...
CVE-2015-0259OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin ...
CVE-2015-0816Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource...
CVE-2015-0815Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6,...
CVE-2015-0814Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to caus...
CVE-2015-0813Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6...
CVE-2015-0812Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows m...
CVE-2015-0811The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from proc...
CVE-2015-0810Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct...
CVE-2015-0808The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incomp...
CVE-2015-0807The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird be...
CVE-2015-0806The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory...
CVE-2015-0805The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call duri...
CVE-2015-0804The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after ...
CVE-2015-0803The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original dat...
CVE-2015-0802Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl ...
CVE-2015-0801Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass ...
CVE-2015-0800The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly gen...
CVE-2015-2809The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast qu...
CVE-2015-2808LOW3.7The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data duri...
CVE-2015-1892The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1...
CVE-2015-2776The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption)...
CVE-2015-2754FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitr...
CVE-2015-2753FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitra...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now