2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3393 | — | — | 2.0% | Oct 10, 2014 | The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), ... |
| CVE-2014-3392 | — | — | 1.7% | Oct 10, 2014 | The Clientless SSL VPN portal in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.... |
| CVE-2014-3391 | — | — | 0.4% | Oct 10, 2014 | Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7(1.13) allows local ... |
| CVE-2014-3390 | — | — | 0.3% | Oct 10, 2014 | The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before 8.7(1.14), 9.2 befor... |
| CVE-2014-3389 | — | — | 2.8% | Oct 10, 2014 | The VPN implementation in Cisco ASA Software 7.2 before 7.2(5.15), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 befor... |
| CVE-2014-3388 | — | — | 1.3% | Oct 10, 2014 | The DNS inspection engine in Cisco ASA Software 9.0 before 9.0(4.13), 9.1 before 9.1(5.7), and 9.2 before 9.2(2) allows ... |
| CVE-2014-3387 | — | — | 1.3% | Oct 10, 2014 | The SunRPC inspection engine in Cisco ASA Software 7.2 before 7.2(5.14), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4... |
| CVE-2014-3386 | — | — | 1.9% | Oct 10, 2014 | The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.... |
| CVE-2014-3385 | — | — | 1.0% | Oct 10, 2014 | Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42... |
| CVE-2014-3384 | — | — | 1.6% | Oct 10, 2014 | The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 ... |
| CVE-2014-3383 | — | — | 1.3% | Oct 10, 2014 | The IKE implementation in the VPN component in Cisco ASA Software 9.1 before 9.1(5.1) allows remote attackers to cause a... |
| CVE-2014-3382 | — | — | 1.4% | Oct 10, 2014 | The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.... |
| CVE-2014-7226 | — | — | 9.2% | Oct 10, 2014 | The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary... |
| CVE-2014-7047 | — | — | 0.3% | Oct 10, 2014 | The Ocean Avenue Mobile Pro (aka com.oceanavenue.mobile) application 2.0 for Android does not verify X.509 certificates ... |
| CVE-2014-7046 | — | — | 0.3% | Oct 10, 2014 | The George Wassouf (aka com.devkhr32.georgewassouf) application 1.0 for Android does not verify X.509 certificates from ... |
| CVE-2014-6439 | — | — | 2.0% | Oct 10, 2014 | Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote att... |
| CVE-2014-5351 | — | — | 2.6% | Oct 10, 2014 | The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1... |
| CVE-2014-5298 | — | — | 3.0% | Oct 10, 2014 | FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attack... |
| CVE-2014-5297 | — | — | 2.7% | Oct 10, 2014 | The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote... |
| CVE-2014-5270 | — | — | 0.5% | Oct 10, 2014 | Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciph... |
| CVE-2014-4661 | — | — | 2.2% | Oct 10, 2014 | Cross-site scripting (XSS) vulnerability in HP Records Manager before 7.3.5 and 8.x before 8.1 Patch 3 allows remote att... |
| CVE-2014-3405 | — | — | 0.7% | Oct 10, 2014 | Cisco IOS XE enables the IPv6 Routing Protocol for Low-Power and Lossy Networks (aka RPL) on both the Autonomic Control ... |
| CVE-2014-3404 | — | — | 0.6% | Oct 10, 2014 | The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which a... |
| CVE-2014-3403 | — | — | 0.6% | Oct 10, 2014 | The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which a... |
| CVE-2014-3201 | — | — | 0.8% | Oct 10, 2014 | core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android,... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now