Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2015-6176

Published Dec 9, 2015

Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6175

Published Dec 9, 2015

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

CVSS 7.8 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2015-6170

Published Dec 9, 2015

Microsoft Edge allows remote attackers to gain privileges via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability."

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6169

Published Dec 9, 2015

Microsoft Edge misparses HTTP responses, which allows remote attackers to redirect users to arbitrary web sites via unspecified vectors, aka "Microsoft Edge Spoofing Vulnerability…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6168

Published Dec 9, 2015

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vul…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6166

Published Dec 9, 2015

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or write access) via unspecified ope…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6165

Published Dec 9, 2015

Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6164

Published Dec 9, 2015

Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6162

Published Dec 9, 2015

Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6161

Published Dec 9, 2015

Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6160

Published Dec 9, 2015

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6159

Published Dec 9, 2015

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Mi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6158

Published Dec 9, 2015

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Mi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6157

Published Dec 9, 2015

Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6156

Published Dec 9, 2015

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet E…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6155

Published Dec 9, 2015

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6154

Published Dec 9, 2015

Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6153

Published Dec 9, 2015

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Mi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 401-425 of 6,494 CVEsPage 17 of 260