2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0304 | — | — | 8.7% | Jan 13, 2015 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows an... |
| CVE-2015-0303 | — | — | 5.9% | Jan 13, 2015 | Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429... |
| CVE-2015-0302 | — | — | 4.9% | Jan 13, 2015 | Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429... |
| CVE-2015-0301 | — | — | 5.2% | Jan 13, 2015 | Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429... |
| CVE-2015-0016 | HIGH | 7.8 | 75.9% | Jan 13, 2015 | Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 ... |
| CVE-2015-0015 | — | — | 78.7% | Jan 13, 2015 | Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cau... |
| CVE-2015-0014 | — | — | 96.9% | Jan 13, 2015 | Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2015-0011 | — | — | 2.0% | Jan 13, 2015 | mrxdav.sys (aka the WebDAV driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W... |
| CVE-2015-0006 | — | — | 11.6% | Jan 13, 2015 | The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 200... |
| CVE-2015-0004 | — | — | 3.5% | Jan 13, 2015 | The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 ... |
| CVE-2015-0002 | — | — | 13.8% | Jan 13, 2015 | The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1,... |
| CVE-2015-0001 | — | — | 2.6% | Jan 13, 2015 | The Windows Error Reporting (WER) component in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wi... |
| CVE-2015-0582 | — | — | 3.0% | Jan 10, 2015 | The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of ser... |
| CVE-2015-0564 | — | — | 2.8% | Jan 10, 2015 | Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.1... |
| CVE-2015-0563 | — | — | 2.4% | Jan 10, 2015 | epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an ... |
| CVE-2015-0562 | — | — | 2.6% | Jan 10, 2015 | Multiple use-after-free vulnerabilities in epan/dissectors/packet-dec-dnart.c in the DEC DNA Routing Protocol dissector ... |
| CVE-2015-0561 | — | — | 5.6% | Jan 10, 2015 | asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a ce... |
| CVE-2015-0560 | — | — | 1.6% | Jan 10, 2015 | The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10... |
| CVE-2015-0559 | — | — | 1.6% | Jan 10, 2015 | Multiple use-after-free vulnerabilities in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x befor... |
| CVE-2015-0922 | — | — | 13.3% | Jan 9, 2015 | McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers'... |
| CVE-2015-0921 | — | — | 17.4% | Jan 9, 2015 | XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x... |
| CVE-2015-0206 | — | — | 59.3% | Jan 9, 2015 | Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allow... |
| CVE-2015-0205 | — | — | 24.6% | Jan 9, 2015 | The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client aut... |
| CVE-2015-0204 | — | — | 98.7% | Jan 9, 2015 | The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k ... |
| CVE-2015-0920 | — | — | 1.2% | Jan 8, 2015 | Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote att... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now