2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4441 | — | — | 1.9% | Oct 18, 2014 | NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible,... |
| CVE-2014-4440 | — | — | 2.1% | Oct 18, 2014 | The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mo... |
| CVE-2014-4439 | — | — | 1.7% | Oct 18, 2014 | Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from a message, which mak... |
| CVE-2014-4438 | — | — | 0.2% | Oct 18, 2014 | Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by lever... |
| CVE-2014-4437 | — | — | 1.1% | Oct 18, 2014 | LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application th... |
| CVE-2014-4436 | — | — | 1.5% | Oct 18, 2014 | IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a ... |
| CVE-2014-4435 | — | — | 0.3% | Oct 18, 2014 | The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN ent... |
| CVE-2014-4434 | — | — | 0.4% | Oct 18, 2014 | The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of service (NULL pointer d... |
| CVE-2014-4433 | — | — | 0.5% | Oct 18, 2014 | Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arb... |
| CVE-2014-4432 | — | — | 0.2% | Oct 18, 2014 | fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a setting-update action a... |
| CVE-2014-4431 | — | — | 0.4% | Oct 18, 2014 | Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physically proximate attack... |
| CVE-2014-4430 | — | — | 0.2% | Oct 18, 2014 | CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, wh... |
| CVE-2014-4428 | — | — | 0.7% | Oct 18, 2014 | Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attacke... |
| CVE-2014-4427 | — | — | 1.2% | Oct 18, 2014 | App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility A... |
| CVE-2014-4426 | — | — | 1.3% | Oct 18, 2014 | AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses of all interfaces v... |
| CVE-2014-4425 | — | — | 0.3% | Oct 18, 2014 | CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver beg... |
| CVE-2014-4417 | — | — | 2.2% | Oct 18, 2014 | Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outa... |
| CVE-2014-4391 | — | — | 2.9% | Oct 18, 2014 | The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bun... |
| CVE-2014-4351 | — | — | 3.6% | Oct 18, 2014 | Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a den... |
| CVE-2014-3573 | — | — | 1.8% | Oct 18, 2014 | The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure Do... |
| CVE-2014-6283 | — | — | 1.1% | Oct 17, 2014 | SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not ... |
| CVE-2014-2279 | — | — | 5.2% | Oct 17, 2014 | Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authe... |
| CVE-2014-2278 | — | — | 3.9% | Oct 17, 2014 | Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows... |
| CVE-2014-2995 | — | — | 3.6% | Oct 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo... |
| CVE-2014-2559 | — | — | 3.3% | Oct 17, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now