2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4619EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P0...
CVE-2014-3344Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home ...
CVE-2014-2381Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows loc...
CVE-2014-2380Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows rem...
CVE-2014-0762The CG Automation Software DNP3 driver, used in the ePAQ-9410 Substation Gateway products, does not validate input corr...
CVE-2014-0761The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infi...
CVE-2014-3177Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google ...
CVE-2014-3176Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google ...
CVE-2014-3175Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service o...
CVE-2014-3174modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0....
CVE-2014-3173The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with th...
CVE-2014-3172The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does ...
CVE-2014-3171Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.94, allows remote at...
CVE-2014-3170extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host...
CVE-2014-3169Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome ...
CVE-2014-3168Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows re...
CVE-2014-3596The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain nam...
CVE-2014-3575The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to em...
CVE-2014-5336Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allo...
CVE-2014-5307Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 a...
CVE-2014-5263vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, wh...
CVE-2014-5035The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity...
CVE-2014-3907Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 fo...
CVE-2014-3524Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified...
CVE-2014-3061Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10....

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now