2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9975 | — | — | 0.4% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exi... |
| CVE-2014-9974 | — | — | 0.8% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing... |
| CVE-2014-9973 | — | — | 0.8% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missin... |
| CVE-2014-9972 | — | — | 1.0% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause ... |
| CVE-2014-9971 | — | — | 1.0% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction ... |
| CVE-2014-9969 | — | — | 0.4% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure crypt... |
| CVE-2014-9968 | — | — | 0.9% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists i... |
| CVE-2014-9411 | — | — | 0.8% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offse... |
| CVE-2014-3451 | — | — | 1.8% | Aug 18, 2017 | OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified ... |
| CVE-2014-0146 | — | — | 0.4% | Aug 10, 2017 | The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a d... |
| CVE-2014-0145 | — | — | 0.5% | Aug 10, 2017 | Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (cra... |
| CVE-2014-0143 | — | — | 0.4% | Aug 10, 2017 | Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of s... |
| CVE-2014-0142 | — | — | 0.4% | Aug 10, 2017 | QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero... |
| CVE-2014-9701 | — | — | 2.3% | Aug 9, 2017 | Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers... |
| CVE-2014-6393 | — | — | 1.1% | Aug 9, 2017 | The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Ty... |
| CVE-2014-5144 | — | — | 2.0% | Aug 9, 2017 | Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary... |
| CVE-2014-1235 | — | — | 2.9% | Aug 7, 2017 | Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary co... |
| CVE-2014-9262 | — | — | 7.5% | Aug 7, 2017 | The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. |
| CVE-2014-8903 | — | — | 2.2% | Aug 2, 2017 | IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remo... |
| CVE-2014-8107 | — | — | — | Jul 20, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-10022. Reason: This candidate is a reservation... |
| CVE-2014-0052 | — | — | — | Jul 20, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-7954 | — | — | 0.4% | Jul 7, 2017 | Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4... |
| CVE-2014-7953 | — | — | 0.3% | Jul 7, 2017 | Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb ... |
| CVE-2014-8149 | — | — | — | Jun 27, 2017 | OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files. |
| CVE-2014-6354 | — | — | — | Jun 27, 2017 | Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet E... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now