2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9975In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exi...
CVE-2014-9974In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing...
CVE-2014-9973In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missin...
CVE-2014-9972In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause ...
CVE-2014-9971In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction ...
CVE-2014-9969In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure crypt...
CVE-2014-9968In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i...
CVE-2014-9411In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offse...
CVE-2014-3451OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified ...
CVE-2014-0146The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a d...
CVE-2014-0145Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (cra...
CVE-2014-0143Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of s...
CVE-2014-0142QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero...
CVE-2014-9701Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers...
CVE-2014-6393The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Ty...
CVE-2014-5144Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary...
CVE-2014-1235Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary co...
CVE-2014-9262The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
CVE-2014-8903IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remo...
CVE-2014-8107Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-10022. Reason: This candidate is a reservation...
CVE-2014-0052Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2014-7954Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4...
CVE-2014-7953Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb ...
CVE-2014-8149OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.
CVE-2014-6354Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet E...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now