CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

CVE-2015-7755

Critical KEV

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or…

Published: Dec 19, 2015
Modified: Oct 22, 2025
Product: juniper screenos
EPSS: 88.72%
View Details
7.8

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

Published: Dec 09, 2015
Modified: Oct 22, 2025
Product: microsoft windows_10_1507
EPSS: 2.92%
View Details
7.5

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

Published: Nov 25, 2015
Modified: Oct 22, 2025
Product: jenkins jenkins
EPSS: 27.39%
View Details
5.3

CVE-2015-4902

Medium KEV

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

Published: Oct 22, 2015
Modified: Oct 22, 2025
Product: redhat enterprise_linux_for_scientific_computing
EPSS: 9.04%
View Details
7.8

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

Published: Oct 15, 2015
Modified: Oct 22, 2025
Product: redhat enterprise_linux_server
EPSS: 85.50%
View Details
8.2

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption…

Published: Sep 09, 2015
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 39.93%
View Details
7.8

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

Published: Sep 09, 2015
Modified: Oct 22, 2025
Product: microsoft office
EPSS: 93.45%
View Details
8.8

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

Published: Aug 19, 2015
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 22.56%
View Details
6.6

CVE-2015-1769

Medium KEV

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted…

Published: Aug 15, 2015
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 28.43%
View Details
7.8

Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Published: Aug 15, 2015
Modified: Oct 22, 2025
Product: microsoft office
EPSS: 72.88%
View Details
8.8

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in…

Published: Aug 08, 2015
Modified: Oct 22, 2025
Product: redhat enterprise_linux_server
EPSS: 71.57%
View Details
8.8

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via…

Published: Jul 20, 2015
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 91.75%
View Details
9.8

CVE-2015-2590

Critical KEV

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Published: Jul 16, 2015
Modified: Oct 22, 2025
Product: redhat enterprise_linux_server
EPSS: 61.54%
View Details
7.8

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via…

Published: Jul 14, 2015
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 31.21%
View Details
8.8

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2384.

Published: Jul 14, 2015
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 31.04%
View Details
8.8

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

Published: Jul 14, 2015
Modified: Oct 22, 2025
Product: microsoft word
EPSS: 83.15%
View Details
9.8

CVE-2015-5123

Critical KEV

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute…

Published: Jul 14, 2015
Modified: Nov 17, 2025
Product: adobe flash_player
EPSS: 47.56%
View Details
9.8

CVE-2015-5122

Critical KEV

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute…

Published: Jul 14, 2015
Modified: Nov 17, 2025
Product: adobe flash_player
EPSS: 92.78%
View Details
9.8

CVE-2015-5119

Critical KEV

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

Published: Jul 08, 2015
Modified: Nov 17, 2025
Product: adobe flash_player
EPSS: 93.08%
View Details
9.8

CVE-2015-3113

Critical KEV

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

Published: Jun 23, 2015
Modified: Nov 17, 2025
Product: hp version_control_repository_manager
EPSS: 92.77%
View Details
8.8

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or…

Published: Jun 10, 2015
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 13.23%
View Details
8.8

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

Published: Jun 10, 2015
Modified: Oct 22, 2025
Product: microsoft office
EPSS: 78.19%
View Details
9.1

CVE-2015-4068

Critical KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

Published: May 29, 2015
Modified: Oct 22, 2025
Product: arcserve udp
EPSS: 81.94%
View Details
7.8

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime…

Published: May 13, 2015
Modified: Oct 22, 2025
Product: microsoft .net_framework
EPSS: 83.86%
View Details