2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-5525The MoMinis library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle atta...
CVE-2014-5524The Adcolony library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2014-5464Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al...
CVE-2014-5369Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, ...
CVE-2014-3618Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service...
CVE-2014-0153The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obta...
CVE-2014-0152Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack w...
CVE-2014-5256Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that trigger...
CVE-2014-4863The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote atta...
CVE-2014-4862The Netmaster CBW700N cable modem with software 81.447.392110.729.024 has an SNMP community of public, which allows remo...
CVE-2014-3910Emurasoft EmFTP allows local users to gain privileges via a Trojan horse executable file that is launched during an atte...
CVE-2014-3909Session fixation vulnerability in Falcon WisePoint 4.1.19.7 and earlier allows remote attackers to hijack web sessions v...
CVE-2014-2379Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, whic...
CVE-2014-2378Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity...
CVE-2014-0877IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restriction...
CVE-2014-6252Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20...
CVE-2014-6029TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an e...
CVE-2014-6028TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies...
CVE-2014-5508Multiple integer overflows in the HelpServ module (mod-helpserv.c) in srvx 1.3.1 allow remote authenticated IRCops or He...
CVE-2014-5036The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, ...
CVE-2014-0863The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 store...
CVE-2014-0610The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers...
CVE-2014-6060The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service...
CVE-2014-5506Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connectio...
CVE-2014-5505Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now