2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1604 | — | — | 0.4% | Jan 28, 2014 | The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof ... |
| CVE-2014-0647 | — | — | 0.4% | Jan 28, 2014 | The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/... |
| CVE-2014-1664 | — | — | 3.1% | Jan 26, 2014 | The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which a... |
| CVE-2014-1607 | — | — | 1.3% | Jan 26, 2014 | Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject a... |
| CVE-2014-0794 | — | — | 1.4% | Jan 26, 2014 | SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authentic... |
| CVE-2014-1666 | — | — | 0.9% | Jan 26, 2014 | The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to th... |
| CVE-2014-1642 | — | — | 0.4% | Jan 26, 2014 | The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, fr... |
| CVE-2014-0022 | — | — | 2.4% | Jan 26, 2014 | The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of... |
| CVE-2014-1673 | — | — | 1.6% | Jan 26, 2014 | Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via ... |
| CVE-2014-1672 | — | — | 0.9% | Jan 26, 2014 | Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table... |
| CVE-2014-1671 | — | — | 1.9% | Jan 26, 2014 | Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remot... |
| CVE-2014-1626 | — | — | 1.5% | Jan 26, 2014 | XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, per... |
| CVE-2014-0027 | — | — | 0.3% | Jan 26, 2014 | The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a s... |
| CVE-2014-0751 | — | — | 3.1% | Jan 25, 2014 | The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into t... |
| CVE-2014-0750 | — | — | 70.2% | Jan 25, 2014 | Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI... |
| CVE-2014-0678 | — | — | 1.4% | Jan 25, 2014 | The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote ... |
| CVE-2014-0673 | — | — | 2.2% | Jan 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cam... |
| CVE-2014-1670 | — | — | 13.7% | Jan 25, 2014 | The Microsoft Bing application before 4.2.1 for Android allows remote attackers to install arbitrary APK files via vecto... |
| CVE-2014-1202 | — | — | 7.7% | Jan 25, 2014 | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a c... |
| CVE-2014-1476 | — | — | 1.1% | Jan 24, 2014 | The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restri... |
| CVE-2014-1475 | — | — | 1.5% | Jan 24, 2014 | The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other user... |
| CVE-2014-1447 | — | — | 2.3% | Jan 24, 2014 | Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause... |
| CVE-2014-0028 | — | — | 0.6% | Jan 24, 2014 | libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains r... |
| CVE-2014-1252 | — | — | 4.2% | Jan 24, 2014 | Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary ... |
| CVE-2014-0809 | — | — | 1.5% | Jan 24, 2014 | Directory traversal vulnerability in the Gapless Player SimZip (aka Simple Zip Viewer) application before 1.2.1 for Andr... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now