2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4619 | — | — | 4.4% | Aug 28, 2014 | EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P0... |
| CVE-2014-3344 | — | — | 2.0% | Aug 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home ... |
| CVE-2014-2381 | — | — | 0.1% | Aug 28, 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows loc... |
| CVE-2014-2380 | — | — | 0.8% | Aug 28, 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows rem... |
| CVE-2014-0762 | — | — | 0.3% | Aug 28, 2014 | The CG Automation Software DNP3 driver, used in the ePAQ-9410 Substation Gateway products, does not validate input corr... |
| CVE-2014-0761 | — | — | 2.0% | Aug 28, 2014 | The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infi... |
| CVE-2014-3177 | — | — | 3.9% | Aug 27, 2014 | Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google ... |
| CVE-2014-3176 | — | — | 9.8% | Aug 27, 2014 | Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google ... |
| CVE-2014-3175 | — | — | 1.5% | Aug 27, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service o... |
| CVE-2014-3174 | — | — | 1.6% | Aug 27, 2014 | modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.... |
| CVE-2014-3173 | — | — | 1.6% | Aug 27, 2014 | The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with th... |
| CVE-2014-3172 | — | — | 1.9% | Aug 27, 2014 | The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does ... |
| CVE-2014-3171 | — | — | 1.6% | Aug 27, 2014 | Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.94, allows remote at... |
| CVE-2014-3170 | — | — | 1.9% | Aug 27, 2014 | extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host... |
| CVE-2014-3169 | — | — | 2.6% | Aug 27, 2014 | Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome ... |
| CVE-2014-3168 | — | — | 1.8% | Aug 27, 2014 | Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows re... |
| CVE-2014-3596 | — | — | 5.8% | Aug 27, 2014 | The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain nam... |
| CVE-2014-3575 | — | — | 9.9% | Aug 27, 2014 | The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to em... |
| CVE-2014-5336 | — | — | 2.5% | Aug 26, 2014 | Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allo... |
| CVE-2014-5307 | — | — | 0.6% | Aug 26, 2014 | Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 a... |
| CVE-2014-5263 | — | — | 1.6% | Aug 26, 2014 | vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, wh... |
| CVE-2014-5035 | — | — | 2.5% | Aug 26, 2014 | The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity... |
| CVE-2014-3907 | — | — | 1.1% | Aug 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 fo... |
| CVE-2014-3524 | — | — | 14.6% | Aug 26, 2014 | Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified... |
| CVE-2014-3061 | — | — | 0.6% | Aug 26, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now