2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3537 | — | — | 0.4% | Jul 23, 2014 | The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack o... |
| CVE-2014-1561 | — | — | 2.1% | Jul 23, 2014 | Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which ... |
| CVE-2014-1560 | — | — | 1.1% | Jul 23, 2014 | Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certi... |
| CVE-2014-1559 | — | — | 1.7% | Jul 23, 2014 | Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certi... |
| CVE-2014-1558 | — | — | 1.2% | Jul 23, 2014 | Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certi... |
| CVE-2014-1557 | — | — | 4.9% | Jul 23, 2014 | The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thu... |
| CVE-2014-1556 | — | — | 3.8% | Jul 23, 2014 | Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute... |
| CVE-2014-1555 | — | — | 4.9% | Jul 23, 2014 | Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x be... |
| CVE-2014-1552 | — | — | 1.3% | Jul 23, 2014 | Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME el... |
| CVE-2014-1551 | — | — | 4.7% | Jul 23, 2014 | Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7... |
| CVE-2014-1550 | — | — | 4.9% | Jul 23, 2014 | Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allo... |
| CVE-2014-1549 | — | — | 5.6% | Jul 23, 2014 | The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbi... |
| CVE-2014-1548 | — | — | 5.8% | Jul 23, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunderbird before 31.0 al... |
| CVE-2014-1547 | — | — | 5.6% | Jul 23, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7,... |
| CVE-2014-1544 | — | — | 6.1% | Jul 23, 2014 | Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services ... |
| CVE-2014-4948 | — | — | 1.9% | Jul 22, 2014 | Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of servi... |
| CVE-2014-4947 | — | — | 5.4% | Jul 22, 2014 | Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified i... |
| CVE-2014-3530 | — | — | 3.9% | Jul 22, 2014 | The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Ent... |
| CVE-2014-3518 | — | — | 2.6% | Jul 22, 2014 | jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss... |
| CVE-2014-5023 | — | — | 3.4% | Jul 22, 2014 | Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary comman... |
| CVE-2014-5022 | — | — | 1.0% | Jul 22, 2014 | Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject ... |
| CVE-2014-5021 | — | — | 1.1% | Jul 22, 2014 | Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows r... |
| CVE-2014-5020 | — | — | 1.3% | Jul 22, 2014 | The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authent... |
| CVE-2014-5019 | — | — | 2.8% | Jul 22, 2014 | The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service... |
| CVE-2014-4911 | — | — | 2.4% | Jul 22, 2014 | The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attacke... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now