2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9975——In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exi...
CVE-2014-9974——In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing...
CVE-2014-9973——In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missin...
CVE-2014-9972——In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause ...
CVE-2014-9971——In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction ...
CVE-2014-9969——In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure crypt...
CVE-2014-9968——In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i...
CVE-2014-9411——In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offse...
CVE-2014-3451——OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified ...
CVE-2014-0146——The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a d...
CVE-2014-0145——Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (cra...
CVE-2014-0143——Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of s...
CVE-2014-0142——QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero...
CVE-2014-9701——Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers...
CVE-2014-6393——The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Ty...
CVE-2014-5144——Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary...
CVE-2014-1235——Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary co...
CVE-2014-9262——The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
CVE-2014-8903——IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remo...
CVE-2014-8107——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-10022. Reason: This candidate is a reservation...
CVE-2014-0052——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2014-7954——Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4...
CVE-2014-7953——Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb ...
CVE-2014-8149——OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.
CVE-2014-6354——Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet E...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now