2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5288 | HIGH | 8.8 | 1.6% | Feb 7, 2020 | A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages. |
| CVE-2014-7224 | HIGH | 8.8 | 2.0% | Feb 7, 2020 | A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the acc... |
| CVE-2014-6413 | MEDIUM | 6.1 | 1.2% | Feb 7, 2020 | A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/p... |
| CVE-2014-9530 | CRITICAL | 9.8 | 1.2% | Feb 7, 2020 | A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impac... |
| CVE-2014-2875 | MEDIUM | 6.1 | 1.6% | Feb 6, 2020 | The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which al... |
| CVE-2014-10400 | MEDIUM | 6.1 | 1.2% | Feb 6, 2020 | The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predi... |
| CVE-2014-10399 | MEDIUM | 6.1 | 1.3% | Feb 6, 2020 | The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbit... |
| CVE-2014-8271 | MEDIUM | 6.8 | 0.4% | Feb 6, 2020 | Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain... |
| CVE-2014-2030 | HIGH | 8.8 | 11.1% | Feb 6, 2020 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remot... |
| CVE-2014-1958 | HIGH | 8.8 | 3.5% | Feb 6, 2020 | Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attacke... |
| CVE-2014-3893 | — | — | — | Feb 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0114. Reason: This candidate is a duplicate of C... |
| CVE-2014-8328 | MEDIUM | 5.3 | 1.6% | Feb 3, 2020 | The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attacker... |
| CVE-2014-8141 | HIGH | 7.8 | 7.4% | Jan 31, 2020 | Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to exe... |
| CVE-2014-2025 | CRITICAL | 9.8 | 4.0% | Jan 31, 2020 | Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5... |
| CVE-2014-8338 | MEDIUM | 6.1 | 1.3% | Jan 31, 2020 | Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhis... |
| CVE-2014-8322 | CRITICAL | 9.8 | 23.9% | Jan 31, 2020 | Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac... |
| CVE-2014-8321 | HIGH | 7.8 | 0.8% | Jan 31, 2020 | Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local use... |
| CVE-2014-8140 | HIGH | 7.8 | 7.4% | Jan 31, 2020 | Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to ex... |
| CVE-2014-8139 | HIGH | 7.8 | 7.4% | Jan 31, 2020 | Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execut... |
| CVE-2014-8126 | HIGH | 8.8 | 3.1% | Jan 31, 2020 | The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code. |
| CVE-2014-5236 | HIGH | 7.5 | 3.8% | Jan 31, 2020 | Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 a... |
| CVE-2014-5039 | CRITICAL | 9.6 | 1.2% | Jan 31, 2020 | Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attacke... |
| CVE-2014-3868 | HIGH | 8.8 | 2.5% | Jan 31, 2020 | Multiple SQL injection vulnerabilities in ZeusCart 4.x. |
| CVE-2014-3809 | MEDIUM | 6.1 | 0.9% | Jan 31, 2020 | Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS... |
| CVE-2014-3119 | HIGH | 8.8 | 1.7% | Jan 31, 2020 | Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitr... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now