2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-1777Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, ...
CVE-2014-1775Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2014-1774Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor...
CVE-2014-1773Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2014-1772Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me...
CVE-2014-1771SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same durin...
CVE-2014-1769Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-0296The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server ...
CVE-2014-0282Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2014-4017Cross-site scripting (XSS) vulnerability in the Conversion Ninja plugin for WordPress allows remote attackers to inject ...
CVE-2014-3880The (1) execve and (2) fexecve system calls in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 10....
CVE-2014-3873The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an ...
CVE-2014-3465The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows rem...
CVE-2014-3216GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg...
CVE-2014-0220Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration i...
CVE-2014-3294Cisco WebEx Meeting Server does not properly restrict the content of URLs, which allows remote authenticated users to ob...
CVE-2014-3292The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote a...
CVE-2014-3289Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Applianc...
CVE-2014-3287SQL injection vulnerability in BulkViewFileContentsAction.java in the Java interface in Cisco Unified Communications Man...
CVE-2014-3042IBM CICS Transaction Server 3.1, 3.2, 4.1, 4.2, and 5.1 on z/OS does not properly implement CEMT transactions, which all...
CVE-2014-4012SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecif...
CVE-2014-4011SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspeci...
CVE-2014-4010SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via uns...
CVE-2014-4009SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access ...
CVE-2014-4008SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain acces...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now