2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-1237Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary...
CVE-2014-0980Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f...
CVE-2014-1876The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u...
CVE-2014-1213Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3....
CVE-2014-1931The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid passw...
CVE-2014-1930Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and respon...
CVE-2014-1916The (1) opus_packet_get_nb_frames and (2) opus_packet_get_samples_per_frame functions in the client in MumbleKit before ...
CVE-2014-1869Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by...
CVE-2014-0045The needSamples method in AudioOutputSpeech.cpp in the client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots, Mumbl...
CVE-2014-0044The opus_packet_get_samples_per_frame function in client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots allows remo...
CVE-2014-0039Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arb...
CVE-2014-1915Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem...
CVE-2014-1914Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote att...
CVE-2014-1699Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-servi...
CVE-2014-1698Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read a...
CVE-2014-1697The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitr...
CVE-2014-1696Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for re...
CVE-2014-1643The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allo...
CVE-2014-1870Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-...
CVE-2014-0822The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a d...
CVE-2014-0330Cross-site scripting (XSS) vulnerability in adminui/user_list.php on the Dell KACE K1000 management appliance 5.5.90545 ...
CVE-2014-0815The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an inter...
CVE-2014-0622The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 ...
CVE-2014-0038The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo...
CVE-2014-1663Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now