2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0610The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers...
CVE-2014-6060The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service...
CVE-2014-5506Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connectio...
CVE-2014-5505Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data ...
CVE-2014-5504SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obt...
CVE-2014-5461Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attacker...
CVE-2014-5377ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc...
CVE-2014-5269Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to b...
CVE-2014-3574Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumpt...
CVE-2014-3529The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file contai...
CVE-2014-2972expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and exe...
CVE-2014-2957The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers...
CVE-2014-2685The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zen...
CVE-2014-5285Unspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x ...
CVE-2014-4805IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local us...
CVE-2014-4759An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 ...
CVE-2014-4758IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated u...
CVE-2014-3353Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a deni...
CVE-2014-3095The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on ...
CVE-2014-3094Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux...
CVE-2014-3075Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombard...
CVE-2014-5465Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress...
CVE-2014-1567Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and...
CVE-2014-1566Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during process...
CVE-2014-1565The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefo...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now