2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5177 | — | — | 0.5% | Aug 3, 2014 | libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitr... |
| CVE-2014-0179 | — | — | 0.6% | Aug 3, 2014 | libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a cra... |
| CVE-2014-5165 | — | — | 2.8% | Aug 1, 2014 | The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1... |
| CVE-2014-5164 | — | — | 2.8% | Aug 1, 2014 | The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initia... |
| CVE-2014-5163 | — | — | 3.3% | Aug 1, 2014 | The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP an... |
| CVE-2014-5162 | — | — | 2.5% | Aug 1, 2014 | The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.... |
| CVE-2014-5161 | — | — | 2.5% | Aug 1, 2014 | The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not ... |
| CVE-2014-5160 | — | — | 34.8% | Aug 1, 2014 | Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote at... |
| CVE-2014-5077 | — | — | 5.8% | Aug 1, 2014 | The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is e... |
| CVE-2014-5045 | — | — | 0.5% | Aug 1, 2014 | The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain refere... |
| CVE-2014-3534 | — | — | 0.5% | Aug 1, 2014 | arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-spac... |
| CVE-2014-0972 | — | — | 0.4% | Aug 1, 2014 | The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions fo... |
| CVE-2014-3302 | — | — | 1.0% | Aug 1, 2014 | user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenti... |
| CVE-2014-3009 | — | — | 0.6% | Aug 1, 2014 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Mast... |
| CVE-2014-2627 | — | — | 1.1% | Aug 1, 2014 | Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01... |
| CVE-2014-5176 | — | — | 2.3% | Jul 31, 2014 | SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via ... |
| CVE-2014-5175 | — | — | 2.0% | Jul 31, 2014 | The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspeci... |
| CVE-2014-5174 | — | — | 1.9% | Jul 31, 2014 | The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 f... |
| CVE-2014-5173 | — | — | 2.8% | Jul 31, 2014 | SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a priva... |
| CVE-2014-5172 | — | — | 2.5% | Jul 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to... |
| CVE-2014-5171 | — | — | 1.5% | Jul 31, 2014 | SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authent... |
| CVE-2014-3554 | — | — | 2.8% | Jul 31, 2014 | Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (c... |
| CVE-2014-3488 | — | — | 4.2% | Jul 31, 2014 | The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consump... |
| CVE-2014-2970 | — | — | — | Jul 31, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5139. Reason: This candidate is a duplicate of... |
| CVE-2014-5117 | — | — | 2.1% | Jul 30, 2014 | Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now