2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7907 | — | — | 1.6% | Nov 19, 2014 | Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used ... |
| CVE-2014-7906 | — | — | 2.0% | Nov 19, 2014 | Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause... |
| CVE-2014-7905 | — | — | 1.1% | Nov 19, 2014 | Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL l... |
| CVE-2014-7904 | — | — | 1.6% | Nov 19, 2014 | Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of serv... |
| CVE-2014-7903 | — | — | 1.5% | Nov 19, 2014 | Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attacker... |
| CVE-2014-7902 | — | — | 1.2% | Nov 19, 2014 | Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a... |
| CVE-2014-7901 | — | — | 1.4% | Nov 19, 2014 | Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDF... |
| CVE-2014-7900 | — | — | 1.4% | Nov 19, 2014 | Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp... |
| CVE-2014-7899 | — | — | 1.3% | Nov 19, 2014 | Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the ... |
| CVE-2014-7996 | — | — | 0.6% | Nov 18, 2014 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco ... |
| CVE-2014-7829 | — | — | 4.2% | Nov 18, 2014 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails... |
| CVE-2014-4817 | — | — | 0.6% | Nov 18, 2014 | The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attack... |
| CVE-2014-8598 | — | — | 39.4% | Nov 18, 2014 | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb... |
| CVE-2014-8475 | — | — | 1.7% | Nov 18, 2014 | FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking s... |
| CVE-2014-7824 | — | — | 0.6% | Nov 18, 2014 | D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denia... |
| CVE-2014-7146 | — | — | 51.6% | Nov 18, 2014 | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr... |
| CVE-2014-3620 | — | — | 4.9% | Nov 18, 2014 | cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sit... |
| CVE-2014-3613 | — | — | 7.4% | Nov 18, 2014 | cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attacke... |
| CVE-2014-4463 | — | — | 0.3% | Nov 18, 2014 | Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or... |
| CVE-2014-4462 | — | — | 1.3% | Nov 18, 2014 | WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code o... |
| CVE-2014-4461 | — | — | 3.4% | Nov 18, 2014 | The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metad... |
| CVE-2014-4460 | — | — | 0.4% | Nov 18, 2014 | CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition... |
| CVE-2014-4459 | — | — | 4.6% | Nov 18, 2014 | Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitra... |
| CVE-2014-4458 | — | — | 1.5% | Nov 18, 2014 | The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-mo... |
| CVE-2014-4457 | — | — | 2.6% | Nov 18, 2014 | The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now