2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0099 | — | — | 8.8% | May 31, 2014 | Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.... |
| CVE-2014-0096 | — | — | 6.9% | May 31, 2014 | java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before ... |
| CVE-2014-0095 | — | — | 8.5% | May 31, 2014 | java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause ... |
| CVE-2014-0075 | — | — | 20.1% | May 31, 2014 | Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Ap... |
| CVE-2014-2354 | — | — | 0.7% | May 30, 2014 | Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent att... |
| CVE-2014-2353 | — | — | 2.5% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web ... |
| CVE-2014-2352 | — | — | 2.3% | May 30, 2014 | The directory specifier can include designators that can be used to traverse the directory path. Exploiting this vulner... |
| CVE-2014-2343 | — | — | 0.3% | May 30, 2014 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of servi... |
| CVE-2014-2342 | — | — | 1.8% | May 30, 2014 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive ... |
| CVE-2014-0907 | — | — | 0.7% | May 30, 2014 | Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 bef... |
| CVE-2014-0925 | — | — | 1.1% | May 30, 2014 | Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 a... |
| CVE-2014-3865 | — | — | 7.3% | May 30, 2014 | Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files out... |
| CVE-2014-3864 | — | — | 2.8% | May 30, 2014 | Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of th... |
| CVE-2014-3227 | — | — | 1.8% | May 30, 2014 | dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for th... |
| CVE-2014-3010 | — | — | 1.2% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 ... |
| CVE-2014-3924 | — | — | 1.4% | May 30, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attacke... |
| CVE-2014-3923 | — | — | 1.6% | May 30, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress ... |
| CVE-2014-3922 | — | — | 2.1% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.1516 allows... |
| CVE-2014-3921 | — | — | 1.6% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote atta... |
| CVE-2014-3780 | — | — | 2.6% | May 30, 2014 | Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to by... |
| CVE-2014-0202 | — | — | 0.4% | May 30, 2014 | The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh... |
| CVE-2014-3463 | — | — | — | May 30, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-3285 | — | — | 3.0% | May 29, 2014 | Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not prop... |
| CVE-2014-3283 | — | — | 2.2% | May 29, 2014 | Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Commun... |
| CVE-2014-3282 | — | — | 2.0% | May 29, 2014 | The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and ear... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now