2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4836 | — | — | 0.9% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before ... |
| CVE-2014-4833 | — | — | 1.1% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invali... |
| CVE-2014-4830 | — | — | 1.2% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for t... |
| CVE-2014-4828 | — | — | 1.3% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to conduct clickjacking attacks via a c... |
| CVE-2014-4827 | — | — | 0.9% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attac... |
| CVE-2014-4825 | — | — | 0.9% | Oct 19, 2014 | IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not properly implement secure connections, which allows ma... |
| CVE-2014-4822 | — | — | 0.4% | Oct 19, 2014 | IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 befo... |
| CVE-2014-3568 | — | — | 14.0% | Oct 19, 2014 | OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option,... |
| CVE-2014-3567 | — | — | 23.6% | Oct 19, 2014 | Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 bef... |
| CVE-2014-3513 | — | — | 37.1% | Oct 19, 2014 | Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a de... |
| CVE-2014-3408 | — | — | 1.3% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Prime Optical 10 allows remote attackers to injec... |
| CVE-2014-3406 | — | — | 0.9% | Oct 19, 2014 | Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows... |
| CVE-2014-3397 | — | — | 3.8% | Oct 19, 2014 | The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of servi... |
| CVE-2014-3381 | — | — | 1.7% | Oct 19, 2014 | The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly... |
| CVE-2014-3370 | — | — | 2.3% | Oct 19, 2014 | Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to caus... |
| CVE-2014-3369 | — | — | 2.4% | Oct 19, 2014 | The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 a... |
| CVE-2014-3368 | — | — | 3.9% | Oct 19, 2014 | Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause ... |
| CVE-2014-3021 | — | — | 2.2% | Oct 19, 2014 | IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properl... |
| CVE-2014-2647 | — | — | 3.4% | Oct 19, 2014 | Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio... |
| CVE-2014-2358 | — | — | 0.6% | Oct 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative web interface in the proxy server on Fo... |
| CVE-2014-4447 | — | — | 0.3% | Oct 18, 2014 | Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file aft... |
| CVE-2014-4446 | — | — | 1.4% | Oct 18, 2014 | Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows r... |
| CVE-2014-4444 | — | — | 0.3% | Oct 18, 2014 | SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, wh... |
| CVE-2014-4443 | — | — | 2.6% | Oct 18, 2014 | Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.... |
| CVE-2014-4442 | — | — | 0.3% | Oct 18, 2014 | The kernel in Apple OS X before 10.10 allows local users to cause a denial of service (panic) via a message to a system ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now