2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2709 | — | — | 4.9% | Apr 23, 2014 | lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacha... |
| CVE-2014-2554 | — | — | 1.5% | Apr 23, 2014 | OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking at... |
| CVE-2014-2328 | — | — | 3.5% | Apr 23, 2014 | lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary command... |
| CVE-2014-2327 | — | — | 2.3% | Apr 23, 2014 | Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack t... |
| CVE-2014-0474 | — | — | 4.8% | Apr 23, 2014 | The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.... |
| CVE-2014-0473 | — | — | 2.0% | Apr 23, 2014 | The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuse... |
| CVE-2014-0472 | — | — | 5.6% | Apr 23, 2014 | The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x... |
| CVE-2014-2154 | — | — | 1.8% | Apr 23, 2014 | Memory leak in the SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to ... |
| CVE-2014-1648 | — | — | 2.1% | Apr 23, 2014 | Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management cons... |
| CVE-2014-1322 | — | — | 1.1% | Apr 23, 2014 | The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s... |
| CVE-2014-1320 | — | — | 0.4% | Apr 23, 2014 | IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an obj... |
| CVE-2014-1321 | — | — | 0.3% | Apr 23, 2014 | Power Management in Apple OS X 10.9.x through 10.9.2 allows physically proximate attackers to bypass an intended transit... |
| CVE-2014-1316 | — | — | 1.1% | Apr 23, 2014 | Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon ex... |
| CVE-2014-1319 | — | — | 1.9% | Apr 23, 2014 | Buffer overflow in ImageIO in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or caus... |
| CVE-2014-1318 | — | — | 2.1% | Apr 23, 2014 | The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attack... |
| CVE-2014-1315 | — | — | 1.8% | Apr 23, 2014 | Format string vulnerability in CoreServicesUIAgent in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execut... |
| CVE-2014-1314 | — | — | 3.1% | Apr 23, 2014 | WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows att... |
| CVE-2014-1296 | — | — | 1.9% | Apr 23, 2014 | CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Coo... |
| CVE-2014-1295 | — | — | 0.9% | Apr 23, 2014 | Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does ... |
| CVE-2014-2900 | — | — | 1.0% | Apr 22, 2014 | wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows... |
| CVE-2014-2899 | — | — | 1.8% | Apr 22, 2014 | wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a re... |
| CVE-2014-2892 | — | — | 6.1% | Apr 22, 2014 | Heap-based buffer overflow in the get_answer function in mmsh.c in libmms before 0.6.4 allows remote attackers to execut... |
| CVE-2014-2890 | — | — | 1.2% | Apr 22, 2014 | Cross-site scripting (XSS) vulnerability in the wrap_html function in MyID.php in phpMyID 0.9 allows remote attackers to... |
| CVE-2014-2737 | — | — | 1.2% | Apr 22, 2014 | SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/... |
| CVE-2014-2659 | — | — | 0.6% | Apr 22, 2014 | Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows r... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now