2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-8511——Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypas...
CVE-2015-8510——Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Fi...
CVE-2015-7939——Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary c...
CVE-2015-7938——Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecifi...
CVE-2015-7575——Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x bef...
CVE-2015-7117——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-7092——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based ...
CVE-2015-7091——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-7090——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-7089——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-7088——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-7087——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-7086——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-7085——Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corr...
CVE-2015-6933——The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x be...
CVE-2015-8766——Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6....
CVE-2015-8376——Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web...
CVE-2015-7541——The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby ...
CVE-2015-8765——Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5....
CVE-2015-8557——The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers...
CVE-2015-4694——Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote...
CVE-2015-8761——The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrat...
CVE-2015-8760——The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains...
CVE-2015-8759——Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allo...
CVE-2015-8758——Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now