2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-7907Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used ...
CVE-2014-7906Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause...
CVE-2014-7905Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL l...
CVE-2014-7904Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of serv...
CVE-2014-7903Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attacker...
CVE-2014-7902Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a...
CVE-2014-7901Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDF...
CVE-2014-7900Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp...
CVE-2014-7899Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the ...
CVE-2014-7996Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco ...
CVE-2014-7829Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails...
CVE-2014-6324HIGH8.8The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 ...
CVE-2014-4817The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attack...
CVE-2014-8598The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb...
CVE-2014-8475FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking s...
CVE-2014-7824D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denia...
CVE-2014-7146The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr...
CVE-2014-3620cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sit...
CVE-2014-3613cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attacke...
CVE-2014-4463Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or...
CVE-2014-4462WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code o...
CVE-2014-4461The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metad...
CVE-2014-4460CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition...
CVE-2014-4459Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitra...
CVE-2014-4458The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-mo...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now