2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0020 | — | — | 2.7% | Feb 6, 2014 | The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC ... |
| CVE-2014-1491 | — | — | 4.7% | Feb 6, 2014 | Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 2... |
| CVE-2014-1490 | — | — | 4.0% | Feb 6, 2014 | Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.... |
| CVE-2014-1489 | — | — | 1.9% | Feb 6, 2014 | Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allo... |
| CVE-2014-1488 | — | — | 7.0% | Feb 6, 2014 | The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execu... |
| CVE-2014-1485 | — | — | 3.0% | Feb 6, 2014 | The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XS... |
| CVE-2014-1484 | — | — | 1.6% | Feb 6, 2014 | Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows... |
| CVE-2014-1483 | — | — | 2.5% | Feb 6, 2014 | Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain... |
| CVE-2014-1480 | — | — | 2.7% | Feb 6, 2014 | The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the... |
| CVE-2014-1478 | — | — | 6.8% | Feb 6, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allo... |
| CVE-2014-1439 | — | — | 1.5% | Feb 5, 2014 | The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) befo... |
| CVE-2014-1833 | — | — | 3.7% | Feb 5, 2014 | Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via ... |
| CVE-2014-1403 | — | — | 1.8% | Feb 5, 2014 | Cross-site scripting (XSS) vulnerability in name.html in easyXDM before 2.4.19 allows remote attackers to inject arbitra... |
| CVE-2014-0755 | — | — | 0.6% | Feb 5, 2014 | Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD fil... |
| CVE-2014-1458 | — | — | 0.8% | Feb 4, 2014 | Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier al... |
| CVE-2014-1694 | — | — | 1.5% | Feb 4, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, ... |
| CVE-2014-1471 | — | — | 1.8% | Feb 4, 2014 | SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System... |
| CVE-2014-0019 | — | — | 0.4% | Feb 4, 2014 | Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a... |
| CVE-2014-0834 | — | — | 1.2% | Feb 4, 2014 | IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial... |
| CVE-2014-0686 | — | — | 0.3% | Feb 4, 2014 | Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges... |
| CVE-2014-0329 | — | — | 8.5% | Feb 4, 2014 | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account... |
| CVE-2014-0015 | — | — | 5.6% | Feb 2, 2014 | cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, w... |
| CVE-2014-0833 | — | — | 1.1% | Feb 1, 2014 | The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-inter... |
| CVE-2014-0832 | — | — | 0.8% | Feb 1, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financi... |
| CVE-2014-0831 | — | — | 0.6% | Feb 1, 2014 | Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 befo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now