2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4455 | — | — | 0.4% | Nov 18, 2014 | dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executa... |
| CVE-2014-4453 | — | — | 1.8% | Nov 18, 2014 | Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions ser... |
| CVE-2014-4452 | — | — | 1.3% | Nov 18, 2014 | WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code o... |
| CVE-2014-4451 | — | — | 0.4% | Nov 18, 2014 | Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proxima... |
| CVE-2014-7992 | — | — | 27.2% | Nov 18, 2014 | The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensiti... |
| CVE-2014-6110 | — | — | 0.6% | Nov 18, 2014 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote atta... |
| CVE-2014-6107 | — | — | 2.4% | Nov 18, 2014 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by ... |
| CVE-2014-6105 | — | — | 2.4% | Nov 18, 2014 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspec... |
| CVE-2014-6098 | — | — | 2.7% | Nov 18, 2014 | IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a craf... |
| CVE-2014-6096 | — | — | 2.3% | Nov 18, 2014 | Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attacker... |
| CVE-2014-6095 | — | — | 3.5% | Nov 18, 2014 | Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to re... |
| CVE-2014-0059 | — | — | 0.3% | Nov 17, 2014 | JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable ... |
| CVE-2014-8955 | — | — | 1.6% | Nov 17, 2014 | Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nich... |
| CVE-2014-8954 | — | — | 3.2% | Nov 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web scr... |
| CVE-2014-8953 | — | — | 2.3% | Nov 17, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to... |
| CVE-2014-8732 | — | — | 2.0% | Nov 17, 2014 | Cross-site scripting (XSS) vulnerability in phpMemcachedAdmin 1.2.2 and earlier allows remote attackers to inject arbitr... |
| CVE-2014-8727 | — | — | 1.0% | Nov 17, 2014 | Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat... |
| CVE-2014-8596 | — | — | 3.3% | Nov 17, 2014 | Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL c... |
| CVE-2014-8517 | — | — | 69.9% | Nov 17, 2014 | The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 thro... |
| CVE-2014-8499 | — | — | 33.6% | Nov 17, 2014 | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Servi... |
| CVE-2014-8498 | — | — | 12.7% | Nov 17, 2014 | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager P... |
| CVE-2014-5277 | — | — | 1.9% | Nov 17, 2014 | Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which ... |
| CVE-2014-3629 | — | — | 6.9% | Nov 17, 2014 | XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause ... |
| CVE-2014-8952 | — | — | 1.5% | Nov 16, 2014 | Multiple unspecified vulnerabilities in Check Point Security Gateway R75.40VS, R75.45, R75.46, R75.47, R76, R77, and R77... |
| CVE-2014-8951 | — | — | 1.5% | Nov 16, 2014 | Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now