2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3188 | — | — | 5.9% | Oct 8, 2014 | Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and ... |
| CVE-2014-3187 | — | — | 0.8% | Oct 8, 2014 | Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facet... |
| CVE-2014-7299 | — | — | 2.1% | Oct 8, 2014 | Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on ... |
| CVE-2014-7275 | — | — | 0.8% | Oct 8, 2014 | The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, wh... |
| CVE-2014-7274 | — | — | 0.8% | Oct 8, 2014 | The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the... |
| CVE-2014-7273 | — | — | 0.9% | Oct 8, 2014 | The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, wh... |
| CVE-2014-7295 | — | — | 1.6% | Oct 7, 2014 | The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.... |
| CVE-2014-7235 | — | — | 43.0% | Oct 7, 2014 | htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, ... |
| CVE-2014-7204 | — | — | 4.3% | Oct 7, 2014 | jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk co... |
| CVE-2014-7189 | — | — | 1.4% | Oct 7, 2014 | crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof c... |
| CVE-2014-6603 | — | — | 3.2% | Oct 7, 2014 | The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass S... |
| CVE-2014-6434 | — | — | 3.2% | Oct 7, 2014 | gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a ... |
| CVE-2014-6433 | — | — | 3.3% | Oct 7, 2014 | gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a sta... |
| CVE-2014-5503 | — | — | 2.0% | Oct 7, 2014 | SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA... |
| CVE-2014-5502 | — | — | 2.3% | Oct 7, 2014 | The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary co... |
| CVE-2014-5501 | — | — | 3.7% | Oct 7, 2014 | Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA a... |
| CVE-2014-3632 | — | — | 2.5% | Oct 7, 2014 | The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red H... |
| CVE-2014-3565 | — | — | 4.6% | Oct 7, 2014 | snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of s... |
| CVE-2014-4871 | — | — | 1.1% | Oct 7, 2014 | Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.... |
| CVE-2014-4870 | — | — | 0.4% | Oct 7, 2014 | /opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 doe... |
| CVE-2014-4869 | — | — | 1.1% | Oct 7, 2014 | The Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows attackers to obtain sensitive encrypted-password info... |
| CVE-2014-4868 | — | — | 2.7% | Oct 7, 2014 | The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users ... |
| CVE-2014-4802 | — | — | 1.1% | Oct 7, 2014 | The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 do... |
| CVE-2014-3399 | — | — | 1.0% | Oct 7, 2014 | The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly m... |
| CVE-2014-0940 | — | — | 1.2% | Oct 7, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Service Automation Manager 7.2.2.2 before 7.2.2.2-TIV-... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now