2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0349 | — | — | 3.8% | Apr 12, 2014 | Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 20... |
| CVE-2014-0347 | — | — | 1.3% | Apr 12, 2014 | The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31... |
| CVE-2014-1210 | — | — | 0.7% | Apr 11, 2014 | VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which a... |
| CVE-2014-1209 | — | — | 3.7% | Apr 11, 2014 | VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Clien... |
| CVE-2014-0636 | — | — | 0.7% | Apr 11, 2014 | EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certi... |
| CVE-2014-1969 | — | — | 1.1% | Apr 11, 2014 | Directory traversal vulnerability in the apps4u@android SD Card Manager application before 20140224 for Android allows a... |
| CVE-2014-0777 | — | — | 2.4% | Apr 11, 2014 | The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers ... |
| CVE-2014-2850 | — | — | 57.6% | Apr 11, 2014 | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator... |
| CVE-2014-2849 | — | — | 60.9% | Apr 11, 2014 | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users ... |
| CVE-2014-2848 | — | — | 0.2% | Apr 11, 2014 | A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain pri... |
| CVE-2014-2847 | — | — | 1.3% | Apr 11, 2014 | SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands ... |
| CVE-2014-0172 | — | — | 4.0% | Apr 11, 2014 | Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and ... |
| CVE-2014-2540 | — | — | 1.3% | Apr 11, 2014 | SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitra... |
| CVE-2014-2333 | — | — | 2.1% | Apr 11, 2014 | Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attacke... |
| CVE-2014-1985 | — | — | 2.7% | Apr 11, 2014 | Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Red... |
| CVE-2014-2829 | — | — | 2.0% | Apr 11, 2014 | Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, w... |
| CVE-2014-2746 | — | — | 3.0% | Apr 11, 2014 | net/IOService.java in Tigase before 5.2.1 does not properly restrict the processing of compressed XML elements, which al... |
| CVE-2014-2745 | — | — | 3.1% | Apr 11, 2014 | Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers... |
| CVE-2014-2744 | — | — | 3.3% | Apr 11, 2014 | plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compr... |
| CVE-2014-2743 | — | — | 1.9% | Apr 11, 2014 | plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed ... |
| CVE-2014-2742 | — | — | 1.8% | Apr 11, 2014 | Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote att... |
| CVE-2014-2741 | — | — | 3.8% | Apr 11, 2014 | nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of comp... |
| CVE-2014-0920 | — | — | 1.6% | Apr 10, 2014 | IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authentic... |
| CVE-2014-0908 | — | — | 1.1% | Apr 10, 2014 | The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, an... |
| CVE-2014-2752 | — | — | 1.5% | Apr 10, 2014 | SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote att... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now