2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2526 | MEDIUM | 6.1 | 1.7% | Mar 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7 allow remote attackers to inject arbitr... |
| CVE-2014-2016 | — | — | 1.5% | Mar 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, ... |
| CVE-2014-2573 | — | — | 0.7% | Mar 25, 2014 | The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, whic... |
| CVE-2014-2386 | — | — | 2.7% | Mar 25, 2014 | Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (... |
| CVE-2014-1515 | — | — | 0.3% | Mar 25, 2014 | Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows at... |
| CVE-2014-1492 | — | — | 1.8% | Mar 25, 2014 | The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Secu... |
| CVE-2014-0628 | — | — | 1.1% | Mar 25, 2014 | The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, w... |
| CVE-2014-0076 | — | — | 0.9% | Mar 25, 2014 | The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a const... |
| CVE-2014-1761 | HIGH | 7.8 | 77.7% | Mar 25, 2014 | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi... |
| CVE-2014-2284 | — | — | 4.4% | Mar 24, 2014 | The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 ... |
| CVE-2014-2568 | — | — | 1.0% | Mar 24, 2014 | Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel thr... |
| CVE-2014-2523 | — | — | 10.4% | Mar 24, 2014 | net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which... |
| CVE-2014-0131 | — | — | 0.7% | Mar 24, 2014 | Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows ... |
| CVE-2014-2589 | — | — | 2.4% | Mar 24, 2014 | Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Sec... |
| CVE-2014-2588 | — | — | 7.3% | Mar 24, 2014 | Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated user... |
| CVE-2014-2587 | — | — | 3.1% | Mar 24, 2014 | SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated user... |
| CVE-2014-2586 | — | — | 3.2% | Mar 24, 2014 | Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote atta... |
| CVE-2014-2585 | — | — | 1.3% | Mar 24, 2014 | ownCloud before 5.0.15 and 6.x before 6.0.2, when the file_external app is enabled, allows remote authenticated users to... |
| CVE-2014-2057 | — | — | 1.0% | Mar 24, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 6.0.2 allow remote attackers to inject arbitrary ... |
| CVE-2014-0016 | — | — | 2.2% | Mar 24, 2014 | stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number g... |
| CVE-2014-2572 | — | — | 1.1% | Mar 24, 2014 | mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, whic... |
| CVE-2014-2571 | — | — | 1.0% | Mar 24, 2014 | Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle throug... |
| CVE-2014-2258 | — | — | 4.6% | Mar 24, 2014 | Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (de... |
| CVE-2014-2254 | — | — | 4.6% | Mar 24, 2014 | Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (de... |
| CVE-2014-2256 | — | — | 3.6% | Mar 24, 2014 | Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (de... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now