2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-3368Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause ...
CVE-2014-3021IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properl...
CVE-2014-2647Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio...
CVE-2014-2358Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative web interface in the proxy server on Fo...
CVE-2014-4447Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file aft...
CVE-2014-4446Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows r...
CVE-2014-4444SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, wh...
CVE-2014-4443Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN....
CVE-2014-4442The kernel in Apple OS X before 10.10 allows local users to cause a denial of service (panic) via a message to a system ...
CVE-2014-4441NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible,...
CVE-2014-4440The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mo...
CVE-2014-4439Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from a message, which mak...
CVE-2014-4438Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by lever...
CVE-2014-4437LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application th...
CVE-2014-4436IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a ...
CVE-2014-4435The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN ent...
CVE-2014-4434The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of service (NULL pointer d...
CVE-2014-4433Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arb...
CVE-2014-4432fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a setting-update action a...
CVE-2014-4431Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physically proximate attack...
CVE-2014-4430CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, wh...
CVE-2014-4428Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attacke...
CVE-2014-4427App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility A...
CVE-2014-4426AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses of all interfaces v...
CVE-2014-4425CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver beg...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now