2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4145——Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-4112——Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-4066——Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-5282——Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image throu...
CVE-2014-5280HIGH8.8boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker d...
CVE-2014-5279——The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, ...
CVE-2014-1835——The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login cr...
CVE-2014-1834——The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary c...
CVE-2014-9504——The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attacke...
CVE-2014-9503——The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated user...
CVE-2014-9502——Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x ...
CVE-2014-3752——The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights...
CVE-2014-3519——The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, w...
CVE-2014-3244——XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to r...
CVE-2014-3005——XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1,...
CVE-2014-1632——htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the ...
CVE-2014-1631——Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
CVE-2014-4705——Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S...
CVE-2014-4919MEDIUM5.4OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before ...
CVE-2014-2017——CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition...
CVE-2014-9485——Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1...
CVE-2014-9482MEDIUM6.5Use-after-free vulnerability in dwarfdump in libdwarf 20130126 through 20140805 might allow remote attackers to cause a ...
CVE-2014-6071——jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the tex...
CVE-2014-6027——Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary we...
CVE-2014-8166HIGH8.8The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now