2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-7907Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used ...
CVE-2014-7906Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause...
CVE-2014-7905Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL l...
CVE-2014-7904Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of serv...
CVE-2014-7903Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attacker...
CVE-2014-7902Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a...
CVE-2014-7901Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDF...
CVE-2014-7900Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp...
CVE-2014-7899Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the ...
CVE-2014-7996Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco ...
CVE-2014-7829Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails...
CVE-2014-4817The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attack...
CVE-2014-8598The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb...
CVE-2014-8475FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking s...
CVE-2014-7824D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denia...
CVE-2014-7146The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr...
CVE-2014-3620cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sit...
CVE-2014-3613cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attacke...
CVE-2014-4463Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or...
CVE-2014-4462WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code o...
CVE-2014-4461The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metad...
CVE-2014-4460CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition...
CVE-2014-4459Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitra...
CVE-2014-4458The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-mo...
CVE-2014-4457The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allo...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now