2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5423 | — | — | 0.3% | Oct 19, 2014 | CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 allows local users to obtain potentially sensit... |
| CVE-2014-5422 | — | — | 2.1% | Oct 19, 2014 | CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded service password, which makes i... |
| CVE-2014-5421 | — | — | 0.3% | Oct 19, 2014 | CareFusion Pyxis SupplyStation 8.1 with hardware test tool 1.0.16 and earlier has a hardcoded database password, which m... |
| CVE-2014-5420 | — | — | 0.9% | Oct 19, 2014 | CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded application password, which mak... |
| CVE-2014-5331 | — | — | 1.1% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in Aflax allows remote attackers to inject arbitrary web script or HTML via uns... |
| CVE-2014-5330 | — | — | 1.1% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in BirdBlog allows remote attackers to inject arbitrary web script or HTML via ... |
| CVE-2014-4840 | — | — | 2.6% | Oct 19, 2014 | IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before ... |
| CVE-2014-4838 | — | — | 0.9% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3... |
| CVE-2014-4837 | — | — | 0.9% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0... |
| CVE-2014-4836 | — | — | 0.9% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before ... |
| CVE-2014-4833 | — | — | 1.1% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invali... |
| CVE-2014-4830 | — | — | 1.2% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for t... |
| CVE-2014-4828 | — | — | 1.3% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to conduct clickjacking attacks via a c... |
| CVE-2014-4827 | — | — | 0.9% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attac... |
| CVE-2014-4825 | — | — | 0.9% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not properly implement secure connections, which allows ma... |
| CVE-2014-4822 | — | — | 0.4% | Oct 19, 2014 | IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 befo... |
| CVE-2014-3568 | — | — | 14.0% | Oct 19, 2014 | OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option,... |
| CVE-2014-3567 | — | — | 23.6% | Oct 19, 2014 | Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 bef... |
| CVE-2014-3513 | — | — | 37.1% | Oct 19, 2014 | Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a de... |
| CVE-2014-3408 | — | — | 1.3% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Prime Optical 10 allows remote attackers to injec... |
| CVE-2014-3406 | — | — | 0.9% | Oct 19, 2014 | Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows... |
| CVE-2014-3397 | — | — | 3.8% | Oct 19, 2014 | The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of servi... |
| CVE-2014-3381 | — | — | 1.7% | Oct 19, 2014 | The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly... |
| CVE-2014-3370 | — | — | 2.3% | Oct 19, 2014 | Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to caus... |
| CVE-2014-3369 | — | — | 2.4% | Oct 19, 2014 | The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 a... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now