2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0257Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it...
CVE-2014-0254The IPv6 implementation in Microsoft Windows 8, Windows Server 2012, and Windows RT does not properly validate packets, ...
CVE-2014-0253Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection stat...
CVE-2014-1459SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra...
CVE-2014-1401Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary ...
CVE-2014-1237Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary...
CVE-2014-0980Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f...
CVE-2014-1876The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u...
CVE-2014-1213Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3....
CVE-2014-1931The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid passw...
CVE-2014-1930Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and respon...
CVE-2014-1916The (1) opus_packet_get_nb_frames and (2) opus_packet_get_samples_per_frame functions in the client in MumbleKit before ...
CVE-2014-1869Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by...
CVE-2014-0045The needSamples method in AudioOutputSpeech.cpp in the client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots, Mumbl...
CVE-2014-0044The opus_packet_get_samples_per_frame function in client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots allows remo...
CVE-2014-0039Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arb...
CVE-2014-1915Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem...
CVE-2014-1914Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote att...
CVE-2014-1699Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-servi...
CVE-2014-1698Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read a...
CVE-2014-1697The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitr...
CVE-2014-1696Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for re...
CVE-2014-1643The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allo...
CVE-2014-1870Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-...
CVE-2014-0822The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a d...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now