2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4441NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible,...
CVE-2014-4440The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mo...
CVE-2014-4439Mail in Apple OS X before 10.10 does not properly recognize the removal of a recipient address from a message, which mak...
CVE-2014-4438Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by lever...
CVE-2014-4437LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application th...
CVE-2014-4436IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a ...
CVE-2014-4435The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN ent...
CVE-2014-4434The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of service (NULL pointer d...
CVE-2014-4433Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arb...
CVE-2014-4432fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a setting-update action a...
CVE-2014-4431Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physically proximate attack...
CVE-2014-4430CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, wh...
CVE-2014-4428Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attacke...
CVE-2014-4427App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility A...
CVE-2014-4426AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses of all interfaces v...
CVE-2014-4425CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver beg...
CVE-2014-4417Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outa...
CVE-2014-4391The Code Signing feature in Apple OS X before 10.10 does not properly handle incomplete resource envelopes in signed bun...
CVE-2014-4351Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a den...
CVE-2014-3573The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure Do...
CVE-2014-6283SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not ...
CVE-2014-2279Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authe...
CVE-2014-2278Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows...
CVE-2014-2995Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo...
CVE-2014-2559Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now