2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1891 | — | — | 0.5% | Apr 1, 2014 | Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID sub... |
| CVE-2014-2590 | — | — | 2.4% | Apr 1, 2014 | The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS ... |
| CVE-2014-0635 | — | — | 1.2% | Apr 1, 2014 | Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web se... |
| CVE-2014-0634 | — | — | 1.0% | Apr 1, 2014 | EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecifi... |
| CVE-2014-0633 | — | — | 0.8% | Apr 1, 2014 | The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might ... |
| CVE-2014-0632 | — | — | 4.5% | Apr 1, 2014 | Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to ... |
| CVE-2014-0050 | — | — | 83.2% | Apr 1, 2014 | MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,... |
| CVE-2014-2034 | — | — | 2.1% | Apr 1, 2014 | Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user ac... |
| CVE-2014-2671 | — | — | 46.0% | Mar 31, 2014 | Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt... |
| CVE-2014-1982 | — | — | 9.8% | Mar 31, 2014 | The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firm... |
| CVE-2014-0983 | — | — | 8.1% | Mar 31, 2014 | Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s... |
| CVE-2014-0982 | — | — | — | Mar 31, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0981. Reason: This issue was MERGED into CVE-201... |
| CVE-2014-0981 | — | — | 1.4% | Mar 31, 2014 | VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x bef... |
| CVE-2014-2669 | — | — | 3.4% | Mar 31, 2014 | Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x b... |
| CVE-2014-0086 | — | — | 1.5% | Mar 31, 2014 | The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers ... |
| CVE-2014-0067 | — | — | 0.5% | Mar 31, 2014 | The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify ... |
| CVE-2014-0066 | — | — | 4.7% | Mar 31, 2014 | The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3... |
| CVE-2014-0065 | — | — | 5.0% | Mar 31, 2014 | Multiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and... |
| CVE-2014-0064 | — | — | 5.4% | Mar 31, 2014 | Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.... |
| CVE-2014-0063 | — | — | 6.7% | Mar 31, 2014 | Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x befor... |
| CVE-2014-0062 | — | — | 3.0% | Mar 31, 2014 | Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x befor... |
| CVE-2014-0061 | — | — | 4.9% | Mar 31, 2014 | The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x befor... |
| CVE-2014-0060 | — | — | 4.1% | Mar 31, 2014 | PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not ... |
| CVE-2014-2670 | — | — | 1.9% | Mar 29, 2014 | Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote au... |
| CVE-2014-1516 | — | — | 1.2% | Mar 29, 2014 | The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now