2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1237 | — | — | 1.7% | Feb 11, 2014 | Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary... |
| CVE-2014-0980 | — | — | 40.4% | Feb 11, 2014 | Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f... |
| CVE-2014-1876 | — | — | 0.5% | Feb 10, 2014 | The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u... |
| CVE-2014-1213 | — | — | 1.0% | Feb 10, 2014 | Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.... |
| CVE-2014-1931 | — | — | 1.1% | Feb 10, 2014 | The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid passw... |
| CVE-2014-1930 | — | — | 1.5% | Feb 10, 2014 | Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and respon... |
| CVE-2014-1916 | — | — | 1.7% | Feb 8, 2014 | The (1) opus_packet_get_nb_frames and (2) opus_packet_get_samples_per_frame functions in the client in MumbleKit before ... |
| CVE-2014-1869 | — | — | 2.8% | Feb 8, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by... |
| CVE-2014-0045 | — | — | 4.0% | Feb 8, 2014 | The needSamples method in AudioOutputSpeech.cpp in the client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots, Mumbl... |
| CVE-2014-0044 | — | — | 2.4% | Feb 8, 2014 | The opus_packet_get_samples_per_frame function in client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots allows remo... |
| CVE-2014-0039 | — | — | 0.6% | Feb 8, 2014 | Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arb... |
| CVE-2014-1915 | — | — | 2.5% | Feb 7, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem... |
| CVE-2014-1914 | — | — | 1.3% | Feb 7, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote att... |
| CVE-2014-1699 | — | — | 2.1% | Feb 7, 2014 | Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-servi... |
| CVE-2014-1698 | — | — | 3.5% | Feb 7, 2014 | Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read a... |
| CVE-2014-1697 | — | — | 5.3% | Feb 7, 2014 | The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitr... |
| CVE-2014-1696 | — | — | 1.7% | Feb 7, 2014 | Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for re... |
| CVE-2014-1643 | — | — | 0.7% | Feb 7, 2014 | The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allo... |
| CVE-2014-1870 | — | — | 1.0% | Feb 6, 2014 | Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-... |
| CVE-2014-0822 | — | — | 1.8% | Feb 6, 2014 | The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a d... |
| CVE-2014-0330 | — | — | 2.2% | Feb 6, 2014 | Cross-site scripting (XSS) vulnerability in adminui/user_list.php on the Dell KACE K1000 management appliance 5.5.90545 ... |
| CVE-2014-0815 | — | — | 1.0% | Feb 6, 2014 | The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an inter... |
| CVE-2014-0622 | — | — | 3.0% | Feb 6, 2014 | The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 ... |
| CVE-2014-0038 | — | — | 34.6% | Feb 6, 2014 | The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo... |
| CVE-2014-1663 | — | — | 2.3% | Feb 6, 2014 | Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now