2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2575 | — | — | 7.3% | Jun 6, 2014 | Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebFor... |
| CVE-2014-2503 | — | — | 2.8% | Jun 6, 2014 | The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P... |
| CVE-2014-3470 | — | — | 85.8% | Jun 5, 2014 | The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before... |
| CVE-2014-0224 | HIGH | 7.4 | 95.3% | Jun 5, 2014 | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph... |
| CVE-2014-0221 | — | — | 87.9% | Jun 5, 2014 | The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.... |
| CVE-2014-0195 | — | — | 100.0% | Jun 5, 2014 | The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0... |
| CVE-2014-3969 | — | — | 0.7% | Jun 5, 2014 | Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows l... |
| CVE-2014-3968 | — | — | 0.7% | Jun 5, 2014 | The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of ... |
| CVE-2014-3967 | — | — | 0.7% | Jun 5, 2014 | The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup... |
| CVE-2014-3469 | — | — | 3.8% | Jun 5, 2014 | The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attac... |
| CVE-2014-3468 | — | — | 3.8% | Jun 5, 2014 | The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is... |
| CVE-2014-3467 | — | — | 6.8% | Jun 5, 2014 | Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote atta... |
| CVE-2014-3976 | — | — | 11.6% | Jun 5, 2014 | Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allow... |
| CVE-2014-3975 | — | — | 6.9% | Jun 5, 2014 | Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via ... |
| CVE-2014-3974 | — | — | 3.2% | Jun 5, 2014 | Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject... |
| CVE-2014-3973 | — | — | 1.3% | Jun 5, 2014 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.3.21 allow remote attackers to execute arbitrary... |
| CVE-2014-3940 | — | — | 0.3% | Jun 5, 2014 | The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to ... |
| CVE-2014-3917 | — | — | 0.4% | Jun 5, 2014 | kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, all... |
| CVE-2014-3912 | — | — | 4.4% | Jun 5, 2014 | Stack-based buffer overflow in the FindConfigChildeKeyList method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 A... |
| CVE-2014-3878 | — | — | 3.5% | Jun 5, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, ... |
| CVE-2014-2577 | — | — | 2.0% | Jun 5, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Transform Content Center in Bottomline Technologies Transform... |
| CVE-2014-2346 | — | — | 0.3% | Jun 5, 2014 | COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (... |
| CVE-2014-2345 | — | — | 1.8% | Jun 5, 2014 | COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (... |
| CVE-2014-1998 | — | — | 0.9% | Jun 5, 2014 | Cross-site scripting (XSS) vulnerability in Nippon Institute of Agroinformatics SOY CMS 1.4.0c and earlier allows remote... |
| CVE-2014-1997 | — | — | 1.8% | Jun 5, 2014 | The ATEN CN8000 remote-access unit with firmware 1.6.154 and earlier allows remote attackers to cause a denial of servic... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now