2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-1221Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a ...
CVE-2015-1220Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp...
CVE-2015-1219Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google C...
CVE-2015-1218Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76...
CVE-2015-1217The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings i...
CVE-2015-1216Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCust...
CVE-2015-1215The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a den...
CVE-2015-1214Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia...
CVE-2015-1213The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrom...
CVE-2015-2192Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD diss...
CVE-2015-2191Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x...
CVE-2015-2190epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater than 32 bits in size,...
CVE-2015-2189Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1....
CVE-2015-2188epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not p...
CVE-2015-2187The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshar...
CVE-2015-0228The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows r...
CVE-2015-2235Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1067. Reason: This candidate is a duplicate of...
CVE-2015-2177HIGH7.5Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via craf...
CVE-2015-1599The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended access restrictions...
CVE-2015-1598The Siemens SPCanywhere application for Android does not properly store application passwords, which allows physically p...
CVE-2015-1597The Siemens SPCanywhere application for Android does not use encryption during the loading of code, which allows man-in-...
CVE-2015-1596The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, wh...
CVE-2015-1595The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of system ID to IP addres...
CVE-2015-1594Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 be...
CVE-2015-0895Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPre...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now