2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3892 | — | — | 1.1% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Nexa Meridian before 2014 allows remote attackers to inject arbitrary web sc... |
| CVE-2014-3886 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attac... |
| CVE-2014-3885 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary we... |
| CVE-2014-3884 | — | — | 1.4% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script ... |
| CVE-2014-3523 | — | — | 16.4% | Jul 20, 2014 | Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x be... |
| CVE-2014-3162 | — | — | 1.0% | Jul 20, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service ... |
| CVE-2014-3161 | — | — | 0.9% | Jul 20, 2014 | The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome be... |
| CVE-2014-3160 | — | — | 1.3% | Jul 20, 2014 | The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.... |
| CVE-2014-3159 | — | — | 0.9% | Jul 20, 2014 | The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegat... |
| CVE-2014-1999 | — | — | 2.7% | Jul 20, 2014 | The auto-format feature in the Request_Curl class in FuelPHP 1.1 through 1.7.1 allows remote attackers to execute arbitr... |
| CVE-2014-1996 | — | — | 2.6% | Jul 20, 2014 | Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbit... |
| CVE-2014-1995 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 all... |
| CVE-2014-1994 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remot... |
| CVE-2014-1993 | — | — | 1.1% | Jul 20, 2014 | The Portlets subsystem in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to bypass intended ... |
| CVE-2014-1992 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the Messages functionality in Cybozu Garoon 3.1.x, 3.5.x, and 3.7.x before 3... |
| CVE-2014-1987 | — | — | 3.2% | Jul 20, 2014 | The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspe... |
| CVE-2014-1973 | — | — | 1.9% | Jul 20, 2014 | Directory traversal vulnerability in the NextApp File Explorer application before 2.1.0.3 for Android allows remote atta... |
| CVE-2014-0231 | — | — | 43.8% | Jul 20, 2014 | The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attac... |
| CVE-2014-0226 | — | — | 85.7% | Jul 20, 2014 | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denia... |
| CVE-2014-0118 | — | — | 37.2% | Jul 20, 2014 | The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when ... |
| CVE-2014-0117 | — | — | 35.5% | Jul 20, 2014 | The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attac... |
| CVE-2014-4331 | — | — | 1.9% | Jul 19, 2014 | Cross-site scripting (XSS) vulnerability in admin/viewer.php in OctavoCMS allows remote attackers to inject arbitrary we... |
| CVE-2014-4943 | — | — | 2.1% | Jul 19, 2014 | The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by ... |
| CVE-2014-3533 | — | — | 0.4% | Jul 19, 2014 | dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certa... |
| CVE-2014-3532 | — | — | 0.4% | Jul 19, 2014 | dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now