2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8512 | — | — | 3.9% | Dec 27, 2014 | Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers t... |
| CVE-2014-8511 | — | — | 4.4% | Dec 27, 2014 | Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers t... |
| CVE-2014-0748 | — | — | 0.3% | Dec 27, 2014 | apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID i... |
| CVE-2014-9420 | — | — | 0.5% | Dec 26, 2014 | The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock Ri... |
| CVE-2014-9419 | — | — | 0.4% | Dec 26, 2014 | The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread ... |
| CVE-2014-7300 | — | — | 0.5% | Dec 25, 2014 | GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption ... |
| CVE-2014-2217 | — | — | 3.7% | Dec 25, 2014 | Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX be... |
| CVE-2014-1449 | — | — | 1.9% | Dec 25, 2014 | The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via... |
| CVE-2014-7193 | — | — | 1.4% | Dec 25, 2014 | The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handl... |
| CVE-2014-3971 | — | — | 1.5% | Dec 25, 2014 | The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x be... |
| CVE-2014-9418 | — | — | 0.7% | Dec 24, 2014 | The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users... |
| CVE-2014-9417 | — | — | 0.6% | Dec 24, 2014 | The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (progr... |
| CVE-2014-9416 | — | — | 0.8% | Dec 24, 2014 | Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute ... |
| CVE-2014-9415 | — | — | 0.6% | Dec 24, 2014 | Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QE... |
| CVE-2014-9414 | — | — | 1.4% | Dec 24, 2014 | The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attack... |
| CVE-2014-9413 | — | — | 1.2% | Dec 24, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the IP Ban (simple-ip-ban) plugin 1.2.3 for WordPress allo... |
| CVE-2014-9334 | — | — | 1.2% | Dec 24, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote at... |
| CVE-2014-9223 | — | — | 6.0% | Dec 24, 2014 | Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and product... |
| CVE-2014-9222 | — | — | 63.5% | Dec 24, 2014 | AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re... |
| CVE-2014-8810 | — | — | 3.7% | Dec 24, 2014 | SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo... |
| CVE-2014-8809 | — | — | 1.7% | Dec 24, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote a... |
| CVE-2014-8138 | — | — | 18.5% | Dec 24, 2014 | Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a d... |
| CVE-2014-8137 | — | — | 14.5% | Dec 24, 2014 | Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers t... |
| CVE-2014-4322 | — | — | 2.0% | Dec 24, 2014 | drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr... |
| CVE-2014-6188 | — | — | 1.5% | Dec 24, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now