2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-5529The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2014-5528The Appsflyer library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle at...
CVE-2014-5527The Tapjoy library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attac...
CVE-2014-5526The Inmobi library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attac...
CVE-2014-5525The MoMinis library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle atta...
CVE-2014-5524The Adcolony library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2014-5464Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al...
CVE-2014-5369Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, ...
CVE-2014-3618Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service...
CVE-2014-0153The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obta...
CVE-2014-0152Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack w...
CVE-2014-5256Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that trigger...
CVE-2014-4863The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote atta...
CVE-2014-4862The Netmaster CBW700N cable modem with software 81.447.392110.729.024 has an SNMP community of public, which allows remo...
CVE-2014-3910Emurasoft EmFTP allows local users to gain privileges via a Trojan horse executable file that is launched during an atte...
CVE-2014-3909Session fixation vulnerability in Falcon WisePoint 4.1.19.7 and earlier allows remote attackers to hijack web sessions v...
CVE-2014-2379Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, whic...
CVE-2014-2378Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity...
CVE-2014-0877IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restriction...
CVE-2014-6252Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20...
CVE-2014-6029TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an e...
CVE-2014-6028TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies...
CVE-2014-5508Multiple integer overflows in the HelpServ module (mod-helpserv.c) in srvx 1.3.1 allow remote authenticated IRCops or He...
CVE-2014-5036The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, ...
CVE-2014-0863The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 store...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now