2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4076 | — | — | 22.7% | Nov 11, 2014 | Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)... |
| CVE-2014-8709 | — | — | 4.5% | Nov 10, 2014 | The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a cert... |
| CVE-2014-8652 | — | — | 2.7% | Nov 10, 2014 | Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via ... |
| CVE-2014-8559 | MEDIUM | 5.5 | 0.7% | Nov 10, 2014 | The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename... |
| CVE-2014-8481 | — | — | 0.6% | Nov 10, 2014 | The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 does not prop... |
| CVE-2014-8480 | — | — | 0.6% | Nov 10, 2014 | The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intende... |
| CVE-2014-8369 | HIGH | 7.8 | 0.6% | Nov 10, 2014 | The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of page... |
| CVE-2014-7826 | HIGH | 7.8 | 0.6% | Nov 10, 2014 | kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during... |
| CVE-2014-7825 | HIGH | 7.8 | 0.6% | Nov 10, 2014 | kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during... |
| CVE-2014-7207 | — | — | 0.4% | Nov 10, 2014 | A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate ar... |
| CVE-2014-3690 | MEDIUM | 5.5 | 0.5% | Nov 10, 2014 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the v... |
| CVE-2014-3687 | HIGH | 7.5 | 8.6% | Nov 10, 2014 | The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through... |
| CVE-2014-3673 | HIGH | 7.5 | 7.5% | Nov 10, 2014 | The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system ... |
| CVE-2014-3647 | MEDIUM | 5.5 | 0.6% | Nov 10, 2014 | arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, wh... |
| CVE-2014-3646 | MEDIUM | 5.5 | 0.4% | Nov 10, 2014 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID... |
| CVE-2014-3645 | — | — | 0.4% | Nov 10, 2014 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT ins... |
| CVE-2014-3611 | MEDIUM | 4.7 | 0.3% | Nov 10, 2014 | Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel ... |
| CVE-2014-3610 | MEDIUM | 5.5 | 0.6% | Nov 10, 2014 | The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the ... |
| CVE-2014-7819 | — | — | 3.9% | Nov 8, 2014 | Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.... |
| CVE-2014-7818 | — | — | 3.5% | Nov 8, 2014 | Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails... |
| CVE-2014-6300 | — | — | 1.9% | Nov 8, 2014 | Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x ... |
| CVE-2014-6161 | — | — | 0.9% | Nov 8, 2014 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool/Impact 6.1.1 before 6.1.1.1-TIV-NCI-IF0001 allows remote ... |
| CVE-2014-6159 | — | — | 2.1% | Nov 8, 2014 | IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immed... |
| CVE-2014-6146 | — | — | 0.3% | Nov 8, 2014 | IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly... |
| CVE-2014-6097 | — | — | 1.9% | Nov 8, 2014 | IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a den... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now