2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5525 | — | — | 0.3% | Sep 9, 2014 | The MoMinis library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle atta... |
| CVE-2014-5524 | — | — | 0.3% | Sep 9, 2014 | The Adcolony library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att... |
| CVE-2014-5464 | — | — | 4.5% | Sep 8, 2014 | Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al... |
| CVE-2014-5369 | — | — | 1.9% | Sep 8, 2014 | Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, ... |
| CVE-2014-3618 | — | — | 8.5% | Sep 8, 2014 | Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service... |
| CVE-2014-0153 | — | — | 1.3% | Sep 8, 2014 | The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obta... |
| CVE-2014-0152 | — | — | 1.8% | Sep 8, 2014 | Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack w... |
| CVE-2014-5256 | — | — | 3.3% | Sep 5, 2014 | Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that trigger... |
| CVE-2014-4863 | — | — | 15.7% | Sep 5, 2014 | The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote atta... |
| CVE-2014-4862 | — | — | 17.1% | Sep 5, 2014 | The Netmaster CBW700N cable modem with software 81.447.392110.729.024 has an SNMP community of public, which allows remo... |
| CVE-2014-3910 | — | — | 0.4% | Sep 5, 2014 | Emurasoft EmFTP allows local users to gain privileges via a Trojan horse executable file that is launched during an atte... |
| CVE-2014-3909 | — | — | 1.3% | Sep 5, 2014 | Session fixation vulnerability in Falcon WisePoint 4.1.19.7 and earlier allows remote attackers to hijack web sessions v... |
| CVE-2014-2379 | — | — | 0.3% | Sep 5, 2014 | Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, whic... |
| CVE-2014-2378 | — | — | 0.9% | Sep 5, 2014 | Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity... |
| CVE-2014-0877 | — | — | 1.2% | Sep 5, 2014 | IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restriction... |
| CVE-2014-6252 | — | — | 2.4% | Sep 5, 2014 | Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20... |
| CVE-2014-6029 | — | — | 1.7% | Sep 5, 2014 | TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an e... |
| CVE-2014-6028 | — | — | 1.7% | Sep 5, 2014 | TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies... |
| CVE-2014-5508 | — | — | 1.1% | Sep 5, 2014 | Multiple integer overflows in the HelpServ module (mod-helpserv.c) in srvx 1.3.1 allow remote authenticated IRCops or He... |
| CVE-2014-5036 | — | — | 0.3% | Sep 5, 2014 | The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, ... |
| CVE-2014-0863 | — | — | 1.1% | Sep 5, 2014 | The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 store... |
| CVE-2014-0610 | — | — | 5.5% | Sep 5, 2014 | The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers... |
| CVE-2014-6060 | — | — | 0.4% | Sep 4, 2014 | The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service... |
| CVE-2014-5506 | — | — | 3.1% | Sep 4, 2014 | Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connectio... |
| CVE-2014-5505 | — | — | 3.8% | Sep 4, 2014 | Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now