2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-8512Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers t...
CVE-2014-8511Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers t...
CVE-2014-0748apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID i...
CVE-2014-9420The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock Ri...
CVE-2014-9419The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread ...
CVE-2014-7300GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption ...
CVE-2014-2217Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX be...
CVE-2014-1449The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via...
CVE-2014-7193The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handl...
CVE-2014-3971The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x be...
CVE-2014-9418The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users...
CVE-2014-9417The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (progr...
CVE-2014-9416Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute ...
CVE-2014-9415Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QE...
CVE-2014-9414The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attack...
CVE-2014-9413Multiple cross-site request forgery (CSRF) vulnerabilities in the IP Ban (simple-ip-ban) plugin 1.2.3 for WordPress allo...
CVE-2014-9334Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote at...
CVE-2014-9223Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and product...
CVE-2014-9222AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re...
CVE-2014-8810SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo...
CVE-2014-8809Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote a...
CVE-2014-8138Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a d...
CVE-2014-8137Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers t...
CVE-2014-4322drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr...
CVE-2014-6188Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now