2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4388 | — | — | 1.7% | Sep 18, 2014 | IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows a... |
| CVE-2014-4386 | — | — | 0.3% | Sep 18, 2014 | Race condition in the App Installation feature in Apple iOS before 8 allows local users to gain privileges and install u... |
| CVE-2014-4384 | — | — | 0.5% | Sep 18, 2014 | Directory traversal vulnerability in the App Installation feature in Apple iOS before 8 allows local users to install un... |
| CVE-2014-4383 | — | — | 1.5% | Sep 18, 2014 | The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device's ... |
| CVE-2014-4381 | — | — | 3.4% | Sep 18, 2014 | Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows att... |
| CVE-2014-4380 | — | — | 3.2% | Sep 18, 2014 | The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write opera... |
| CVE-2014-4379 | — | — | 2.2% | Sep 18, 2014 | An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent ... |
| CVE-2014-4378 | — | — | 5.0% | Sep 18, 2014 | CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive information or caus... |
| CVE-2014-4377 | — | — | 6.9% | Sep 18, 2014 | Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrar... |
| CVE-2014-4375 | — | — | 0.4% | Sep 18, 2014 | Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a d... |
| CVE-2014-4374 | — | — | 2.2% | Sep 18, 2014 | NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an exte... |
| CVE-2014-4373 | — | — | 1.3% | Sep 18, 2014 | The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV before 7 allows atta... |
| CVE-2014-4372 | — | — | 0.4% | Sep 18, 2014 | syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions... |
| CVE-2014-4371 | — | — | 0.4% | Sep 18, 2014 | The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize ... |
| CVE-2014-4369 | — | — | 2.1% | Sep 18, 2014 | The IOAcceleratorFamily API implementation in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denia... |
| CVE-2014-4368 | — | — | 0.4% | Sep 18, 2014 | The Accessibility subsystem in Apple iOS before 8 allows attackers to interfere with screen locking via vectors related ... |
| CVE-2014-4367 | — | — | 0.4% | Sep 18, 2014 | Apple iOS before 8 enables Voice Dial during all upgrade actions, which makes it easier for physically proximate attacke... |
| CVE-2014-4366 | — | — | 2.1% | Sep 18, 2014 | Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote ... |
| CVE-2014-4364 | — | — | 0.8% | Sep 18, 2014 | The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which a... |
| CVE-2014-4363 | — | — | 1.9% | Sep 18, 2014 | Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attac... |
| CVE-2014-4362 | — | — | 1.6% | Sep 18, 2014 | The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile... |
| CVE-2014-4361 | — | — | 1.6% | Sep 18, 2014 | The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, wh... |
| CVE-2014-4357 | — | — | 0.4% | Sep 18, 2014 | Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by readi... |
| CVE-2014-4356 | — | — | 0.4% | Sep 18, 2014 | Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which... |
| CVE-2014-4354 | — | — | 1.0% | Sep 18, 2014 | Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass in... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now