2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4145Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-4112Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-4066Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-5282Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image throu...
CVE-2014-5280HIGH8.8boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker d...
CVE-2014-5279The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, ...
CVE-2014-1835The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login cr...
CVE-2014-1834The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary c...
CVE-2014-9504The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attacke...
CVE-2014-9503The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated user...
CVE-2014-9502Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x ...
CVE-2014-3752The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights...
CVE-2014-3519The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, w...
CVE-2014-3244XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to r...
CVE-2014-3005XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1,...
CVE-2014-1632htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the ...
CVE-2014-1631Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
CVE-2014-4705Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S...
CVE-2014-4919MEDIUM5.4OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before ...
CVE-2014-2017CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition...
CVE-2014-9485Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1...
CVE-2014-9482MEDIUM6.5Use-after-free vulnerability in dwarfdump in libdwarf 20130126 through 20140805 might allow remote attackers to cause a ...
CVE-2014-6071jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the tex...
CVE-2014-6027Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary we...
CVE-2014-8166HIGH8.8The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now