2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0330 | — | — | 2.2% | Feb 6, 2014 | Cross-site scripting (XSS) vulnerability in adminui/user_list.php on the Dell KACE K1000 management appliance 5.5.90545 ... |
| CVE-2014-0815 | — | — | 1.0% | Feb 6, 2014 | The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an inter... |
| CVE-2014-0622 | — | — | 3.0% | Feb 6, 2014 | The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 ... |
| CVE-2014-0038 | — | — | 34.6% | Feb 6, 2014 | The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo... |
| CVE-2014-1663 | — | — | 2.3% | Feb 6, 2014 | Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, ... |
| CVE-2014-0020 | — | — | 2.7% | Feb 6, 2014 | The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC ... |
| CVE-2014-1491 | — | — | 4.7% | Feb 6, 2014 | Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 2... |
| CVE-2014-1490 | — | — | 4.0% | Feb 6, 2014 | Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.... |
| CVE-2014-1489 | — | — | 1.9% | Feb 6, 2014 | Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allo... |
| CVE-2014-1488 | — | — | 7.0% | Feb 6, 2014 | The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execu... |
| CVE-2014-1487 | HIGH | 7.5 | 2.3% | Feb 6, 2014 | The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, an... |
| CVE-2014-1486 | CRITICAL | 9.8 | 7.1% | Feb 6, 2014 | Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.... |
| CVE-2014-1485 | — | — | 3.0% | Feb 6, 2014 | The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XS... |
| CVE-2014-1484 | — | — | 1.6% | Feb 6, 2014 | Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows... |
| CVE-2014-1483 | — | — | 2.5% | Feb 6, 2014 | Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain... |
| CVE-2014-1482 | HIGH | 8.8 | 6.3% | Feb 6, 2014 | RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey bef... |
| CVE-2014-1481 | HIGH | 7.5 | 3.9% | Feb 6, 2014 | Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remo... |
| CVE-2014-1480 | — | — | 2.7% | Feb 6, 2014 | The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the... |
| CVE-2014-1479 | HIGH | 7.5 | 4.6% | Feb 6, 2014 | The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird b... |
| CVE-2014-1478 | — | — | 6.8% | Feb 6, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allo... |
| CVE-2014-1477 | CRITICAL | 9.8 | 5.5% | Feb 6, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3,... |
| CVE-2014-1439 | — | — | 1.5% | Feb 5, 2014 | The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) befo... |
| CVE-2014-1833 | — | — | 3.7% | Feb 5, 2014 | Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via ... |
| CVE-2014-1403 | — | — | 1.8% | Feb 5, 2014 | Cross-site scripting (XSS) vulnerability in name.html in easyXDM before 2.4.19 allows remote attackers to inject arbitra... |
| CVE-2014-0755 | — | — | 0.6% | Feb 5, 2014 | Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD fil... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now