2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2859 | — | — | 2.4% | Apr 15, 2014 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions vi... |
| CVE-2014-0924 | — | — | 1.1% | Apr 15, 2014 | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct... |
| CVE-2014-0923 | — | — | 1.4% | Apr 15, 2014 | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart... |
| CVE-2014-0922 | — | — | 1.3% | Apr 15, 2014 | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consu... |
| CVE-2014-0921 | — | — | 1.3% | Apr 15, 2014 | The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (... |
| CVE-2014-0642 | — | — | 1.0% | Apr 15, 2014 | EMC Documentum Content Server before 6.7 SP1 P26, 6.7 SP2 before P13, 7.0 before P13, and 7.1 before P02 allows remote a... |
| CVE-2014-2384 | — | — | 0.3% | Apr 15, 2014 | vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local ... |
| CVE-2014-1986 | — | — | 1.1% | Apr 15, 2014 | The Content Provider in the KOKUYO CamiApp application 1.21.1 and earlier for Android allows attackers to bypass intende... |
| CVE-2014-0514 | — | — | 72.0% | Apr 15, 2014 | The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r... |
| CVE-2014-2580 | — | — | 0.3% | Apr 15, 2014 | The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local... |
| CVE-2014-0107 | — | — | 13.7% | Apr 15, 2014 | The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FE... |
| CVE-2014-2842 | — | — | 3.5% | Apr 15, 2014 | Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) vi... |
| CVE-2014-2828 | — | — | 3.1% | Apr 15, 2014 | The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attack... |
| CVE-2014-2690 | — | — | 0.3% | Apr 15, 2014 | Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by ... |
| CVE-2014-0167 | — | — | 1.6% | Apr 15, 2014 | The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before ic... |
| CVE-2014-0157 | — | — | 1.2% | Apr 15, 2014 | Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 201... |
| CVE-2014-0139 | — | — | 4.9% | Apr 15, 2014 | cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildca... |
| CVE-2014-0138 | — | — | 5.1% | Apr 15, 2014 | The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) I... |
| CVE-2014-0105 | — | — | 1.1% | Apr 15, 2014 | The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 d... |
| CVE-2014-0359 | — | — | 4.7% | Apr 15, 2014 | Xangati XSR before 11 and XNR before 7 allows remote attackers to execute arbitrary commands via shell metacharacters in... |
| CVE-2014-0358 | — | — | 6.1% | Apr 15, 2014 | Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar... |
| CVE-2014-0357 | — | — | 1.8% | Apr 15, 2014 | Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a... |
| CVE-2014-0356 | — | — | 1.1% | Apr 15, 2014 | The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to execute arbitrary ... |
| CVE-2014-0355 | — | — | 0.6% | Apr 15, 2014 | Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allo... |
| CVE-2014-0354 | — | — | 0.8% | Apr 15, 2014 | The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 has a hardcoded password of qweasdzxc for an ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now