2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2135 | — | — | 3.8% | May 8, 2014 | Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 befo... |
| CVE-2014-2134 | — | — | 3.8% | May 8, 2014 | Heap-based buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T28 before T28.12, and ... |
| CVE-2014-2133 | — | — | 3.1% | May 8, 2014 | Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 befo... |
| CVE-2014-2132 | — | — | 1.6% | May 8, 2014 | Cisco WebEx Recording Format (WRF) player and Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before... |
| CVE-2014-0963 | — | — | 3.1% | May 8, 2014 | The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 befor... |
| CVE-2014-0930 | — | — | 0.5% | May 8, 2014 | The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (sy... |
| CVE-2014-0595 | — | — | 0.3% | May 8, 2014 | /opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not pro... |
| CVE-2014-0362 | — | — | 0.8% | May 8, 2014 | Cross-site scripting (XSS) vulnerability on Google Search Appliance (GSA) devices before 7.0.14.G.216 and 7.2 before 7.2... |
| CVE-2014-0116 | — | — | 6.7% | May 8, 2014 | CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restr... |
| CVE-2014-3124 | — | — | 0.8% | May 7, 2014 | The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of servi... |
| CVE-2014-2913 | — | — | 15.3% | May 7, 2014 | Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote atta... |
| CVE-2014-2891 | — | — | 2.5% | May 7, 2014 | strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon cr... |
| CVE-2014-2191 | — | — | 1.4% | May 7, 2014 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (a... |
| CVE-2014-2190 | — | — | 0.8% | May 7, 2014 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wire... |
| CVE-2014-2181 | — | — | 1.1% | May 7, 2014 | Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted UR... |
| CVE-2014-0911 | — | — | 1.3% | May 7, 2014 | inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of ser... |
| CVE-2014-0685 | — | — | 1.2% | May 7, 2014 | Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements... |
| CVE-2014-0684 | — | — | 0.3% | May 7, 2014 | Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug... |
| CVE-2014-3204 | — | — | 0.5% | May 6, 2014 | Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proxim... |
| CVE-2014-3203 | — | — | 0.5% | May 6, 2014 | Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is activ... |
| CVE-2014-3202 | — | — | 0.4% | May 6, 2014 | Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the ... |
| CVE-2014-2558 | — | — | 1.7% | May 6, 2014 | The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrator... |
| CVE-2014-0193 | — | — | 4.3% | May 6, 2014 | WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0... |
| CVE-2014-2347 | — | — | 2.4% | May 6, 2014 | Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obt... |
| CVE-2014-1736 | — | — | 2.1% | May 6, 2014 | Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now