2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2678 | — | — | 0.4% | Apr 1, 2014 | The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of... |
| CVE-2014-2673 | — | — | 0.4% | Apr 1, 2014 | The arch_dup_task_struct function in the Transactional Memory (TM) implementation in arch/powerpc/kernel/process.c in th... |
| CVE-2014-2672 | — | — | 2.7% | Apr 1, 2014 | Race condition in the ath_tx_aggr_sleep function in drivers/net/wireless/ath/ath9k/xmit.c in the Linux kernel before 3.1... |
| CVE-2014-2237 | — | — | 1.4% | Apr 1, 2014 | The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and iceho... |
| CVE-2014-1896 | — | — | 0.5% | Apr 1, 2014 | The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests... |
| CVE-2014-1895 | — | — | 0.5% | Apr 1, 2014 | Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the ... |
| CVE-2014-1894 | — | — | 0.5% | Apr 1, 2014 | Multiple integer overflows in unspecified suboperations in the flask hypercall in Xen 3.2.x and earlier, when XSM is ena... |
| CVE-2014-1893 | — | — | 0.5% | Apr 1, 2014 | Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.... |
| CVE-2014-1892 | — | — | 0.5% | Apr 1, 2014 | Xen 3.3 through 4.1, when XSM is enabled, allows local users to cause a denial of service via vectors related to a "larg... |
| CVE-2014-1891 | — | — | 0.5% | Apr 1, 2014 | Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID sub... |
| CVE-2014-2590 | — | — | 2.4% | Apr 1, 2014 | The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS ... |
| CVE-2014-0635 | — | — | 1.2% | Apr 1, 2014 | Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web se... |
| CVE-2014-0634 | — | — | 1.0% | Apr 1, 2014 | EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecifi... |
| CVE-2014-0633 | — | — | 0.8% | Apr 1, 2014 | The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might ... |
| CVE-2014-0632 | — | — | 4.5% | Apr 1, 2014 | Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to ... |
| CVE-2014-0050 | — | — | 83.2% | Apr 1, 2014 | MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,... |
| CVE-2014-2034 | — | — | 2.1% | Apr 1, 2014 | Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user ac... |
| CVE-2014-2671 | — | — | 46.0% | Mar 31, 2014 | Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt... |
| CVE-2014-1982 | — | — | 9.8% | Mar 31, 2014 | The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firm... |
| CVE-2014-0983 | — | — | 8.1% | Mar 31, 2014 | Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s... |
| CVE-2014-0982 | — | — | — | Mar 31, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0981. Reason: This issue was MERGED into CVE-201... |
| CVE-2014-0981 | — | — | 1.4% | Mar 31, 2014 | VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x bef... |
| CVE-2014-2669 | — | — | 3.4% | Mar 31, 2014 | Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x b... |
| CVE-2014-0086 | — | — | 1.5% | Mar 31, 2014 | The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers ... |
| CVE-2014-0067 | — | — | 0.5% | Mar 31, 2014 | The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now