2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0771 | — | — | 1.4% | Apr 12, 2014 | The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter a... |
| CVE-2014-0770 | — | — | 2.6% | Apr 12, 2014 | By providing an overly long string to the UserName parameter, an attacker may be able to overflow the static stack buff... |
| CVE-2014-0768 | — | — | 2.7% | Apr 12, 2014 | An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buf... |
| CVE-2014-0767 | — | — | 2.7% | Apr 12, 2014 | An attacker may exploit this vulnerability by passing an overly long value from the AccessCode argument to the control.... |
| CVE-2014-0766 | — | — | 2.7% | Apr 12, 2014 | An attacker can exploit this vulnerability by copying an overly long NodeName2 argument into a statically sized buffer ... |
| CVE-2014-0765 | — | — | 2.7% | Apr 12, 2014 | To exploit this vulnerability, the attacker sends data from the GotoCmd argument to control. If the value of the argume... |
| CVE-2014-0764 | — | — | 2.7% | Apr 12, 2014 | By providing an overly long string to the NodeName parameter, an attacker may be able to overflow the static stack buff... |
| CVE-2014-0763 | — | — | 19.0% | Apr 12, 2014 | An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll i... |
| CVE-2014-0349 | — | — | 3.8% | Apr 12, 2014 | Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 20... |
| CVE-2014-0347 | — | — | 1.3% | Apr 12, 2014 | The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31... |
| CVE-2014-1210 | — | — | 0.7% | Apr 11, 2014 | VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which a... |
| CVE-2014-1209 | — | — | 3.7% | Apr 11, 2014 | VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Clien... |
| CVE-2014-0636 | — | — | 0.7% | Apr 11, 2014 | EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certi... |
| CVE-2014-1969 | — | — | 1.1% | Apr 11, 2014 | Directory traversal vulnerability in the apps4u@android SD Card Manager application before 20140224 for Android allows a... |
| CVE-2014-0777 | — | — | 2.4% | Apr 11, 2014 | The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers ... |
| CVE-2014-2850 | — | — | 57.6% | Apr 11, 2014 | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator... |
| CVE-2014-2849 | — | — | 60.9% | Apr 11, 2014 | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users ... |
| CVE-2014-2848 | — | — | 0.2% | Apr 11, 2014 | A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain pri... |
| CVE-2014-2847 | — | — | 1.3% | Apr 11, 2014 | SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands ... |
| CVE-2014-0172 | — | — | 4.0% | Apr 11, 2014 | Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and ... |
| CVE-2014-2540 | — | — | 1.3% | Apr 11, 2014 | SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitra... |
| CVE-2014-2333 | — | — | 2.1% | Apr 11, 2014 | Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attacke... |
| CVE-2014-1985 | — | — | 2.7% | Apr 11, 2014 | Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Red... |
| CVE-2014-2829 | — | — | 2.0% | Apr 11, 2014 | Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, w... |
| CVE-2014-2746 | — | — | 3.0% | Apr 11, 2014 | net/IOService.java in Tigase before 5.2.1 does not properly restrict the processing of compressed XML elements, which al... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now