2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2260 | — | — | 1.5% | Apr 30, 2014 | Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows ... |
| CVE-2014-3135 | — | — | 1.9% | Apr 30, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 5.1.1 Alpha 9 allow remote attackers to inject arbitrar... |
| CVE-2014-3134 | — | — | 1.2% | Apr 30, 2014 | Cross-site scripting (XSS) vulnerability in the InfoView application in SAP BusinessObjects allows remote attackers to i... |
| CVE-2014-3133 | — | — | 2.1% | Apr 30, 2014 | SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the lis... |
| CVE-2014-3132 | — | — | 1.1% | Apr 30, 2014 | SAP Background Processing does not properly restrict access, which allows remote authenticated users to obtain sensitive... |
| CVE-2014-3131 | — | — | 1.1% | Apr 30, 2014 | SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive i... |
| CVE-2014-3130 | — | — | 0.3% | Apr 30, 2014 | The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does no... |
| CVE-2014-3129 | — | — | 2.3% | Apr 30, 2014 | The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensiti... |
| CVE-2014-2565 | — | — | 0.7% | Apr 30, 2014 | The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to ... |
| CVE-2014-1957 | — | — | 1.1% | Apr 30, 2014 | FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors. |
| CVE-2014-1956 | — | — | 1.5% | Apr 30, 2014 | CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP header... |
| CVE-2014-1955 | — | — | 1.4% | Apr 30, 2014 | Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary... |
| CVE-2014-0471 | — | — | 2.9% | Apr 30, 2014 | Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.... |
| CVE-2014-0470 | — | — | 0.4% | Apr 30, 2014 | super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows loc... |
| CVE-2014-2545 | — | — | 1.8% | Apr 30, 2014 | TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot b... |
| CVE-2014-2186 | — | — | 0.6% | Apr 30, 2014 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attack... |
| CVE-2014-1532 | CRITICAL | 9.8 | 4.6% | Apr 30, 2014 | Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox ... |
| CVE-2014-1531 | HIGH | 8.8 | 5.6% | Apr 30, 2014 | Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0... |
| CVE-2014-1530 | MEDIUM | 6.1 | 1.7% | Apr 30, 2014 | The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and S... |
| CVE-2014-1529 | HIGH | 8.8 | 3.7% | Apr 30, 2014 | The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaM... |
| CVE-2014-1528 | — | — | 5.6% | Apr 30, 2014 | The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Wind... |
| CVE-2014-1527 | — | — | 1.5% | Apr 30, 2014 | Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that... |
| CVE-2014-1526 | — | — | 1.8% | Apr 30, 2014 | The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote atta... |
| CVE-2014-1525 | — | — | 4.4% | Apr 30, 2014 | The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly ... |
| CVE-2014-1524 | CRITICAL | 9.8 | 7.5% | Apr 30, 2014 | The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunder... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now