2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0949 | — | — | 1.2% | May 22, 2014 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.... |
| CVE-2014-3808 | — | — | 1.9% | May 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbi... |
| CVE-2014-3807 | — | — | 1.9% | May 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary w... |
| CVE-2014-3806 | — | — | 7.7% | May 21, 2014 | Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attack... |
| CVE-2014-3803 | — | — | 1.4% | May 21, 2014 | The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable micro... |
| CVE-2014-3152 | — | — | 2.0% | May 21, 2014 | Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.2... |
| CVE-2014-1749 | — | — | 1.0% | May 21, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 35.0.1916.114 allow attackers to cause a denial of service ... |
| CVE-2014-1748 | — | — | 1.5% | May 21, 2014 | The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114... |
| CVE-2014-1747 | — | — | 1.8% | May 21, 2014 | Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoade... |
| CVE-2014-1746 | — | — | 1.4% | May 21, 2014 | The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 ... |
| CVE-2014-1745 | HIGH | 7.1 | 1.7% | May 21, 2014 | Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows r... |
| CVE-2014-1744 | — | — | 1.6% | May 21, 2014 | Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_inp... |
| CVE-2014-1743 | — | — | 1.6% | May 21, 2014 | Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as... |
| CVE-2014-3802 | — | — | 10.9% | May 20, 2014 | msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not... |
| CVE-2014-3792 | — | — | 2.3% | May 20, 2014 | Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote at... |
| CVE-2014-3791 | — | — | 76.2% | May 20, 2014 | Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code ... |
| CVE-2014-3776 | — | — | 4.5% | May 20, 2014 | Buffer overflow in the "read-u8vector!" procedure in the srfi-4 unit in CHICKEN stable 4.8.0.7 and development snapshots... |
| CVE-2014-3749 | — | — | 1.3% | May 20, 2014 | SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the... |
| CVE-2014-3739 | — | — | 1.3% | May 20, 2014 | Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to re... |
| CVE-2014-3738 | — | — | 3.7% | May 20, 2014 | Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML ... |
| CVE-2014-3412 | — | — | 4.7% | May 20, 2014 | Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers... |
| CVE-2014-1855 | — | — | 1.9% | May 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel before 3.5.0 allow remote attackers to inject arbitrary... |
| CVE-2014-3460 | — | — | 3.3% | May 20, 2014 | Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ ... |
| CVE-2014-3444 | — | — | 5.6% | May 20, 2014 | The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to exec... |
| CVE-2014-3273 | — | — | 0.8% | May 20, 2014 | The LLDP implementation in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a malforme... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now