2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-6631Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x before 3.2.5 and 3.3.x before 3.3.4 allows remote...
CVE-2014-5376Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0, when a pre-generated key is used, does not validate that the re...
CVE-2014-5375The server in Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 does not properly validate the message owner match...
CVE-2014-5300Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersona...
CVE-2014-3641The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to o...
CVE-2014-7980Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x befo...
CVE-2014-7979Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authent...
CVE-2014-7978Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authen...
CVE-2014-7205Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t...
CVE-2014-7185Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive informa...
CVE-2014-6394visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the docu...
CVE-2014-5308Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm...
CVE-2014-7967Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allo...
CVE-2014-3200Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service ...
CVE-2014-3199The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome bef...
CVE-2014-3198The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101...
CVE-2014-3197The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google C...
CVE-2014-3196base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only ...
CVE-2014-3195Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as ...
CVE-2014-3194Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attac...
CVE-2014-3193The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101...
CVE-2014-3192Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.c...
CVE-2014-3191Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a...
CVE-2014-3190Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google C...
CVE-2014-3189The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 do...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now