2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1553 | — | — | 5.7% | Sep 3, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1,... |
| CVE-2014-6064 | — | — | 1.3% | Sep 2, 2014 | The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 ... |
| CVE-2014-5521 | — | — | 7.1% | Sep 2, 2014 | plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary co... |
| CVE-2014-5340 | — | — | 6.1% | Sep 2, 2014 | The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which all... |
| CVE-2014-5339 | — | — | 1.8% | Sep 2, 2014 | Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk f... |
| CVE-2014-5137 | — | — | 1.2% | Sep 2, 2014 | Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on... |
| CVE-2014-5136 | — | — | 0.9% | Sep 2, 2014 | Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote a... |
| CVE-2014-0485 | — | — | 4.6% | Sep 2, 2014 | S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code ... |
| CVE-2014-6041 | — | — | 19.9% | Sep 2, 2014 | The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu... |
| CVE-2014-5452 | — | — | 2.1% | Sep 2, 2014 | CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML att... |
| CVE-2014-5076 | — | — | 1.0% | Sep 2, 2014 | The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component ... |
| CVE-2014-3862 | — | — | 1.3% | Sep 2, 2014 | CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted refere... |
| CVE-2014-3861 | — | — | 1.5% | Sep 2, 2014 | Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbit... |
| CVE-2014-5472 | — | — | 0.5% | Sep 1, 2014 | The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to... |
| CVE-2014-5471 | — | — | 0.5% | Sep 1, 2014 | Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel t... |
| CVE-2014-3601 | — | — | 1.2% | Sep 1, 2014 | The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of page... |
| CVE-2014-3908 | — | — | 0.5% | Aug 30, 2014 | The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which al... |
| CVE-2014-3352 | — | — | 2.8% | Aug 30, 2014 | Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whethe... |
| CVE-2014-5247 | — | — | 0.5% | Aug 29, 2014 | The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 be... |
| CVE-2014-5147 | — | — | 0.4% | Aug 29, 2014 | Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use ... |
| CVE-2014-5119 | — | — | 18.1% | Aug 29, 2014 | Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-depe... |
| CVE-2014-5073 | — | — | 73.5% | Aug 29, 2014 | vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands ... |
| CVE-2014-2390 | — | — | 0.7% | Aug 29, 2014 | Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) b... |
| CVE-2014-5337 | — | — | 17.0% | Aug 29, 2014 | The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected post... |
| CVE-2014-5128 | — | — | 2.3% | Aug 29, 2014 | Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attacker... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now