2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4138 | — | — | 32.2% | Oct 15, 2014 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co... |
| CVE-2014-4137 | — | — | 22.7% | Oct 15, 2014 | Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memo... |
| CVE-2014-4134 | — | — | 17.2% | Oct 15, 2014 | Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (... |
| CVE-2014-4133 | — | — | 16.7% | Oct 15, 2014 | Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memo... |
| CVE-2014-4132 | — | — | 16.6% | Oct 15, 2014 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co... |
| CVE-2014-4130 | — | — | 21.2% | Oct 15, 2014 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co... |
| CVE-2014-4129 | — | — | 24.5% | Oct 15, 2014 | Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor... |
| CVE-2014-4128 | — | — | 17.2% | Oct 15, 2014 | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ... |
| CVE-2014-4127 | — | — | 16.4% | Oct 15, 2014 | Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service ... |
| CVE-2014-4126 | — | — | 21.4% | Oct 15, 2014 | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me... |
| CVE-2014-4124 | — | — | 11.6% | Oct 15, 2014 | Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Interne... |
| CVE-2014-4123 | HIGH | 8.8 | 40.3% | Oct 15, 2014 | Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Interne... |
| CVE-2014-4122 | — | — | 13.1% | Oct 15, 2014 | Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to o... |
| CVE-2014-4121 | — | — | 19.2% | Oct 15, 2014 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resourc... |
| CVE-2014-4117 | — | — | 17.5% | Oct 15, 2014 | Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Co... |
| CVE-2014-4115 | — | — | 2.9% | Oct 15, 2014 | fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Ser... |
| CVE-2014-4114 | HIGH | 7.8 | 81.6% | Oct 15, 2014 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2... |
| CVE-2014-4113 | HIGH | 7.8 | 87.0% | Oct 15, 2014 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2014-4075 | — | — | 20.2% | Oct 15, 2014 | Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 thro... |
| CVE-2014-4073 | — | — | 23.4% | Oct 15, 2014 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with... |
| CVE-2014-1586 | — | — | 2.8% | Oct 15, 2014 | content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x befor... |
| CVE-2014-1585 | — | — | 2.8% | Oct 15, 2014 | The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 3... |
| CVE-2014-1584 | — | — | 2.2% | Oct 15, 2014 | The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 skips pinning checks upon an unspecified issu... |
| CVE-2014-1583 | — | — | 2.8% | Oct 15, 2014 | The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly restrict toJSON calls, w... |
| CVE-2014-1582 | — | — | 1.2% | Oct 15, 2014 | The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coa... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now