2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4834 | — | — | 1.3% | Nov 5, 2014 | IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity exp... |
| CVE-2014-4810 | — | — | 1.1% | Nov 5, 2014 | IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between th... |
| CVE-2014-4769 | — | — | 1.2% | Nov 5, 2014 | IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary ... |
| CVE-2014-3710 | — | — | 13.8% | Nov 5, 2014 | The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure ... |
| CVE-2014-2374 | — | — | 1.9% | Nov 5, 2014 | The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords an... |
| CVE-2014-2373 | — | — | 1.8% | Nov 5, 2014 | The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords an... |
| CVE-2014-6033 | — | — | — | Nov 5, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6032. Reason: This candidate is a duplicate of C... |
| CVE-2014-2718 | — | — | 1.1% | Nov 4, 2014 | ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series ... |
| CVE-2014-3461 | — | — | 2.7% | Nov 4, 2014 | hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a h... |
| CVE-2014-0223 | — | — | 0.6% | Nov 4, 2014 | Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of ... |
| CVE-2014-0222 | — | — | 2.1% | Nov 4, 2014 | Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denia... |
| CVE-2014-0182 | — | — | 5.3% | Nov 4, 2014 | Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote att... |
| CVE-2014-8474 | — | — | 2.5% | Nov 4, 2014 | CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to read arbitrary files, send HTTP requests... |
| CVE-2014-8473 | — | — | 1.1% | Nov 4, 2014 | Cross-site request forgery (CSRF) vulnerability in CA Cloud Service Management (CSM) before Summer 2014 allows remote at... |
| CVE-2014-8472 | — | — | 2.2% | Nov 4, 2014 | CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Pro... |
| CVE-2014-8471 | — | — | 1.8% | Nov 4, 2014 | CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to conduct replay attacks via unspecified v... |
| CVE-2014-7875 | — | — | 5.3% | Nov 4, 2014 | Unspecified vulnerability on the HP LaserJet CM3530 Multifunction Printer CC519A and CC520A with firmware before 53.236.... |
| CVE-2014-6130 | — | — | 1.9% | Nov 4, 2014 | The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP sessio... |
| CVE-2014-8593 | — | — | 1.9% | Nov 4, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary ... |
| CVE-2014-4974 | — | — | 0.5% | Nov 4, 2014 | The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212... |
| CVE-2014-3660 | — | — | 4.0% | Nov 4, 2014 | parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disab... |
| CVE-2014-8592 | — | — | 2.1% | Nov 4, 2014 | Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a d... |
| CVE-2014-8591 | — | — | 1.9% | Nov 4, 2014 | Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows rem... |
| CVE-2014-8590 | — | — | 2.2% | Nov 4, 2014 | XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allow... |
| CVE-2014-8589 | — | — | 1.6% | Nov 4, 2014 | Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now