2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4417 | — | — | 2.2% | Oct 18, 2014 | Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outa... |
| CVE-2014-4391 | — | — | 2.9% | Oct 18, 2014 | The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bun... |
| CVE-2014-4351 | — | — | 3.6% | Oct 18, 2014 | Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a den... |
| CVE-2014-3573 | — | — | 1.8% | Oct 18, 2014 | The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure Do... |
| CVE-2014-6283 | — | — | 1.1% | Oct 17, 2014 | SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not ... |
| CVE-2014-2279 | — | — | 5.2% | Oct 17, 2014 | Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authe... |
| CVE-2014-2278 | — | — | 3.9% | Oct 17, 2014 | Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows... |
| CVE-2014-2995 | — | — | 3.6% | Oct 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo... |
| CVE-2014-2559 | — | — | 3.3% | Oct 17, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre... |
| CVE-2014-8756 | — | — | 3.7% | Oct 17, 2014 | The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbi... |
| CVE-2014-8755 | — | — | 2.6% | Oct 17, 2014 | Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which trigge... |
| CVE-2014-8074 | — | — | 3.4% | Oct 17, 2014 | Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 bef... |
| CVE-2014-7960 | — | — | 3.0% | Oct 17, 2014 | OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other m... |
| CVE-2014-2068 | — | — | 1.4% | Oct 17, 2014 | The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 al... |
| CVE-2014-2066 | — | — | 2.1% | Oct 17, 2014 | Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sess... |
| CVE-2014-2065 | — | — | 1.8% | Oct 17, 2014 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to injec... |
| CVE-2014-2064 | — | — | 3.0% | Oct 17, 2014 | The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS befor... |
| CVE-2014-2063 | — | — | 2.3% | Oct 17, 2014 | Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vect... |
| CVE-2014-2062 | — | — | 1.7% | Oct 17, 2014 | Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remot... |
| CVE-2014-2061 | — | — | 2.0% | Oct 17, 2014 | The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers ... |
| CVE-2014-2060 | — | — | 1.5% | Oct 17, 2014 | The Winstone servlet container in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack sessions... |
| CVE-2014-2058 | — | — | 1.8% | Oct 17, 2014 | BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restricti... |
| CVE-2014-8320 | — | — | 1.1% | Oct 17, 2014 | Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14... |
| CVE-2014-8319 | — | — | 1.0% | Oct 17, 2014 | Cross-site scripting (XSS) vulnerability in the easy_social_admin_summary function in the Easy Social module 7.x-2.x bef... |
| CVE-2014-8318 | — | — | 1.1% | Oct 17, 2014 | Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now