2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-1553Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1,...
CVE-2014-6064The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 ...
CVE-2014-5521plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary co...
CVE-2014-5340The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which all...
CVE-2014-5339Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk f...
CVE-2014-5137Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on...
CVE-2014-5136Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote a...
CVE-2014-0485S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code ...
CVE-2014-6041The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu...
CVE-2014-5452CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML att...
CVE-2014-5076The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component ...
CVE-2014-3862CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted refere...
CVE-2014-3861Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbit...
CVE-2014-5472The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to...
CVE-2014-5471Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel t...
CVE-2014-3601The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of page...
CVE-2014-3908The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which al...
CVE-2014-3352Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whethe...
CVE-2014-5247The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 be...
CVE-2014-5147Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use ...
CVE-2014-5119Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-depe...
CVE-2014-5073vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands ...
CVE-2014-2390Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) b...
CVE-2014-5337The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected post...
CVE-2014-5128Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attacker...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now