2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0610 | — | — | 5.5% | Sep 5, 2014 | The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers... |
| CVE-2014-6060 | — | — | 0.4% | Sep 4, 2014 | The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service... |
| CVE-2014-5506 | — | — | 3.1% | Sep 4, 2014 | Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connectio... |
| CVE-2014-5505 | — | — | 3.8% | Sep 4, 2014 | Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data ... |
| CVE-2014-5504 | — | — | 5.4% | Sep 4, 2014 | SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obt... |
| CVE-2014-5461 | — | — | 11.6% | Sep 4, 2014 | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attacker... |
| CVE-2014-5377 | — | — | 57.5% | Sep 4, 2014 | ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc... |
| CVE-2014-5269 | — | — | 2.5% | Sep 4, 2014 | Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to b... |
| CVE-2014-3574 | — | — | 7.4% | Sep 4, 2014 | Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumpt... |
| CVE-2014-3529 | — | — | 13.3% | Sep 4, 2014 | The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file contai... |
| CVE-2014-2972 | — | — | 0.5% | Sep 4, 2014 | expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and exe... |
| CVE-2014-2957 | — | — | 5.3% | Sep 4, 2014 | The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers... |
| CVE-2014-2685 | — | — | 2.8% | Sep 4, 2014 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zen... |
| CVE-2014-5285 | — | — | 2.0% | Sep 4, 2014 | Unspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x ... |
| CVE-2014-4805 | — | — | 0.4% | Sep 4, 2014 | IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local us... |
| CVE-2014-4759 | — | — | 1.1% | Sep 4, 2014 | An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 ... |
| CVE-2014-4758 | — | — | 1.1% | Sep 4, 2014 | IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated u... |
| CVE-2014-3353 | — | — | 2.5% | Sep 4, 2014 | Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a deni... |
| CVE-2014-3095 | — | — | 2.1% | Sep 4, 2014 | The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on ... |
| CVE-2014-3094 | — | — | 5.0% | Sep 4, 2014 | Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux... |
| CVE-2014-3075 | — | — | 0.9% | Sep 4, 2014 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombard... |
| CVE-2014-5465 | — | — | 13.5% | Sep 3, 2014 | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress... |
| CVE-2014-1567 | — | — | 4.9% | Sep 3, 2014 | Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and... |
| CVE-2014-1566 | — | — | 1.2% | Sep 3, 2014 | Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during process... |
| CVE-2014-1565 | — | — | 2.8% | Sep 3, 2014 | The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now