2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0771The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter a...
CVE-2014-0770By providing an overly long string to the UserName parameter, an attacker may be able to overflow the static stack buff...
CVE-2014-0768An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buf...
CVE-2014-0767An attacker may exploit this vulnerability by passing an overly long value from the AccessCode argument to the control....
CVE-2014-0766An attacker can exploit this vulnerability by copying an overly long NodeName2 argument into a statically sized buffer ...
CVE-2014-0765To exploit this vulnerability, the attacker sends data from the GotoCmd argument to control. If the value of the argume...
CVE-2014-0764By providing an overly long string to the NodeName parameter, an attacker may be able to overflow the static stack buff...
CVE-2014-0763An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll i...
CVE-2014-0349Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 20...
CVE-2014-0347The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31...
CVE-2014-1210VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which a...
CVE-2014-1209VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Clien...
CVE-2014-0636EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certi...
CVE-2014-1969Directory traversal vulnerability in the apps4u@android SD Card Manager application before 20140224 for Android allows a...
CVE-2014-0777The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers ...
CVE-2014-2850The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator...
CVE-2014-2849The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users ...
CVE-2014-2848A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain pri...
CVE-2014-2847SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands ...
CVE-2014-0172Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and ...
CVE-2014-2540SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitra...
CVE-2014-2333Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attacke...
CVE-2014-1985Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Red...
CVE-2014-2829Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, w...
CVE-2014-2746net/IOService.java in Tigase before 5.2.1 does not properly restrict the processing of compressed XML elements, which al...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now