2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5504 | — | — | 5.4% | Sep 4, 2014 | SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obt... |
| CVE-2014-5461 | — | — | 11.6% | Sep 4, 2014 | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attacker... |
| CVE-2014-5377 | — | — | 57.5% | Sep 4, 2014 | ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc... |
| CVE-2014-5269 | — | — | 2.5% | Sep 4, 2014 | Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to b... |
| CVE-2014-3574 | — | — | 7.4% | Sep 4, 2014 | Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumpt... |
| CVE-2014-3529 | — | — | 13.3% | Sep 4, 2014 | The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file contai... |
| CVE-2014-2972 | — | — | 0.5% | Sep 4, 2014 | expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and exe... |
| CVE-2014-2957 | — | — | 5.3% | Sep 4, 2014 | The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers... |
| CVE-2014-2685 | — | — | 2.8% | Sep 4, 2014 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zen... |
| CVE-2014-5285 | — | — | 2.0% | Sep 4, 2014 | Unspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x ... |
| CVE-2014-4805 | — | — | 0.4% | Sep 4, 2014 | IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local us... |
| CVE-2014-4759 | — | — | 1.1% | Sep 4, 2014 | An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 ... |
| CVE-2014-4758 | — | — | 1.1% | Sep 4, 2014 | IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated u... |
| CVE-2014-3353 | — | — | 2.5% | Sep 4, 2014 | Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a deni... |
| CVE-2014-3095 | — | — | 2.1% | Sep 4, 2014 | The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on ... |
| CVE-2014-3094 | — | — | 5.0% | Sep 4, 2014 | Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux... |
| CVE-2014-3075 | — | — | 0.9% | Sep 4, 2014 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombard... |
| CVE-2014-5465 | — | — | 13.5% | Sep 3, 2014 | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress... |
| CVE-2014-1567 | — | — | 4.9% | Sep 3, 2014 | Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and... |
| CVE-2014-1566 | — | — | 1.2% | Sep 3, 2014 | Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during process... |
| CVE-2014-1565 | — | — | 2.8% | Sep 3, 2014 | The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefo... |
| CVE-2014-1564 | — | — | 5.5% | Sep 3, 2014 | Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize m... |
| CVE-2014-1563 | — | — | 5.8% | Sep 3, 2014 | Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox E... |
| CVE-2014-1562 | — | — | 5.6% | Sep 3, 2014 | Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x be... |
| CVE-2014-1554 | — | — | 5.8% | Sep 3, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to caus... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now