2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9325 | — | — | 1.9% | Dec 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in TWiki 6.0.1 allow remote attackers to inject arbitrary web script... |
| CVE-2014-9254 | — | — | 1.3% | Dec 31, 2014 | bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to c... |
| CVE-2014-8752 | — | — | 1.1% | Dec 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in view.php in JCE-Tech PHP Video Script (aka Video Niche Script) 4.... |
| CVE-2014-9426 | HIGH | 7.3 | 2.1% | Dec 31, 2014 | The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform... |
| CVE-2014-9425 | — | — | 3.7% | Dec 31, 2014 | Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP thro... |
| CVE-2014-4634 | — | — | 0.4% | Dec 30, 2014 | Unquoted Windows search path vulnerability in EMC Replication Manager through 5.5.2 and AppSync before 2.1.0 allows loca... |
| CVE-2014-4630 | — | — | 0.9% | Dec 30, 2014 | EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.6 and RSA BSAFE SSL-J before 6.1.4 do not ensure that a server'... |
| CVE-2014-8109 | — | — | 22.0% | Dec 29, 2014 | mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd confi... |
| CVE-2014-3556 | — | — | 7.8% | Dec 29, 2014 | The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and ... |
| CVE-2014-2224 | — | — | 1.4% | Dec 29, 2014 | Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it ... |
| CVE-2014-1908 | — | — | 7.2% | Dec 29, 2014 | The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Li... |
| CVE-2014-1905 | — | — | 10.4% | Dec 29, 2014 | Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin befo... |
| CVE-2014-6168 | — | — | 0.5% | Dec 29, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remot... |
| CVE-2014-6160 | — | — | 0.6% | Dec 29, 2014 | IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not prop... |
| CVE-2014-6123 | — | — | 0.3% | Dec 29, 2014 | IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2,... |
| CVE-2014-9424 | — | — | 1.8% | Dec 29, 2014 | Double free vulnerability in the ssl_parse_clienthello_use_srtp_ext function in d1_srtp.c in LibreSSL before 2.1.2 allow... |
| CVE-2014-8132 | — | — | 5.1% | Dec 29, 2014 | Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remo... |
| CVE-2014-6229 | — | — | 1.7% | Dec 28, 2014 | The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectl... |
| CVE-2014-6228 | — | — | 1.9% | Dec 28, 2014 | Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Mach... |
| CVE-2014-5386 | — | — | 1.5% | Dec 28, 2014 | The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before... |
| CVE-2014-2209 | — | — | 2.1% | Dec 28, 2014 | Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capabi... |
| CVE-2014-2208 | — | — | 2.7% | Dec 28, 2014 | CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipH... |
| CVE-2014-9188 | — | — | 6.1% | Dec 27, 2014 | Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers... |
| CVE-2014-8514 | — | — | 4.0% | Dec 27, 2014 | Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers... |
| CVE-2014-8513 | — | — | 2.9% | Dec 27, 2014 | Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now