2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0761 | — | — | 2.0% | Aug 28, 2014 | The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infi... |
| CVE-2014-3177 | — | — | 3.9% | Aug 27, 2014 | Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google ... |
| CVE-2014-3176 | — | — | 9.8% | Aug 27, 2014 | Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google ... |
| CVE-2014-3175 | — | — | 1.5% | Aug 27, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service o... |
| CVE-2014-3174 | — | — | 1.6% | Aug 27, 2014 | modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.... |
| CVE-2014-3173 | — | — | 1.6% | Aug 27, 2014 | The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with th... |
| CVE-2014-3172 | — | — | 1.9% | Aug 27, 2014 | The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does ... |
| CVE-2014-3171 | — | — | 1.6% | Aug 27, 2014 | Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.94, allows remote at... |
| CVE-2014-3170 | — | — | 1.9% | Aug 27, 2014 | extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host... |
| CVE-2014-3169 | — | — | 2.6% | Aug 27, 2014 | Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome ... |
| CVE-2014-3168 | — | — | 1.8% | Aug 27, 2014 | Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows re... |
| CVE-2014-3596 | — | — | 5.8% | Aug 27, 2014 | The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain nam... |
| CVE-2014-3575 | — | — | 9.9% | Aug 27, 2014 | The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to em... |
| CVE-2014-5336 | — | — | 2.5% | Aug 26, 2014 | Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allo... |
| CVE-2014-5307 | — | — | 0.6% | Aug 26, 2014 | Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 a... |
| CVE-2014-5263 | — | — | 1.6% | Aug 26, 2014 | vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, wh... |
| CVE-2014-5035 | — | — | 2.5% | Aug 26, 2014 | The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity... |
| CVE-2014-3907 | — | — | 1.1% | Aug 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 fo... |
| CVE-2014-3524 | — | — | 14.6% | Aug 26, 2014 | Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified... |
| CVE-2014-3061 | — | — | 0.6% | Aug 26, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.... |
| CVE-2014-3041 | — | — | 1.0% | Aug 26, 2014 | SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 i... |
| CVE-2014-3035 | — | — | 0.9% | Aug 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, ... |
| CVE-2014-3034 | — | — | 0.9% | Aug 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x befo... |
| CVE-2014-2528 | — | — | 2.9% | Aug 26, 2014 | kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers ... |
| CVE-2014-2527 | — | — | 3.0% | Aug 26, 2014 | kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now