2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1387 | — | — | 2.8% | Aug 14, 2014 | WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1386 | — | — | 2.4% | Aug 14, 2014 | WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1385 | — | — | 2.8% | Aug 14, 2014 | WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1384 | — | — | 2.8% | Aug 14, 2014 | WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-5239 | — | — | 2.9% | Aug 14, 2014 | The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL se... |
| CVE-2014-4345 | — | — | 8.1% | Aug 14, 2014 | Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP ... |
| CVE-2014-4344 | — | — | 6.6% | Aug 14, 2014 | The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x t... |
| CVE-2014-4343 | — | — | 6.4% | Aug 14, 2014 | Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c i... |
| CVE-2014-3898 | — | — | 1.8% | Aug 14, 2014 | Cross-site scripting (XSS) vulnerability in Fujitsu ServerView Operations Manager 5.00.09 through 6.30.05 allows remote ... |
| CVE-2014-1980 | — | — | 1.2% | Aug 14, 2014 | Cross-site scripting (XSS) vulnerability in include/functions_metadata.inc.php in Piwigo before 2.4.6 allows remote atta... |
| CVE-2014-5139 | — | — | 20.0% | Aug 13, 2014 | The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a den... |
| CVE-2014-3512 | — | — | 74.1% | Aug 13, 2014 | Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote ... |
| CVE-2014-3511 | — | — | 13.3% | Aug 13, 2014 | The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to f... |
| CVE-2014-3510 | — | — | 16.9% | Aug 13, 2014 | The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 ... |
| CVE-2014-3509 | — | — | 13.4% | Aug 13, 2014 | Race condition in the ssl_parse_serverhello_tlsext function in t1_lib.c in OpenSSL 1.0.0 before 1.0.0n and 1.0.1 before ... |
| CVE-2014-3508 | — | — | 23.3% | Aug 13, 2014 | The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 bef... |
| CVE-2014-3507 | — | — | 51.4% | Aug 13, 2014 | Memory leak in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 befo... |
| CVE-2014-3506 | — | — | 44.2% | Aug 13, 2014 | d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allow... |
| CVE-2014-3505 | — | — | 43.3% | Aug 13, 2014 | Double free vulnerability in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, ... |
| CVE-2014-5157 | — | — | — | Aug 13, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5196. Reason: This candidate is a reservation ... |
| CVE-2014-3167 | — | — | 1.2% | Aug 13, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.143 allow attackers to cause a denial of service ... |
| CVE-2014-3166 | — | — | 1.5% | Aug 13, 2014 | The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and befor... |
| CVE-2014-3165 | — | — | 1.6% | Aug 13, 2014 | Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web Sockets implementatio... |
| CVE-2014-5202 | — | — | 1.5% | Aug 12, 2014 | Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote... |
| CVE-2014-3901 | — | — | 2.3% | Aug 12, 2014 | Raritan Japan Dominion KX2-101 switches before 2 allow remote attackers to cause a denial of service (device hang) via a... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now