2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0027 | — | — | 0.3% | Jan 26, 2014 | The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a s... |
| CVE-2014-0751 | — | — | 3.1% | Jan 25, 2014 | The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into t... |
| CVE-2014-0750 | — | — | 70.2% | Jan 25, 2014 | Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI... |
| CVE-2014-0678 | — | — | 1.4% | Jan 25, 2014 | The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote ... |
| CVE-2014-0673 | — | — | 2.2% | Jan 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cam... |
| CVE-2014-1670 | — | — | 13.7% | Jan 25, 2014 | The Microsoft Bing application before 4.2.1 for Android allows remote attackers to install arbitrary APK files via vecto... |
| CVE-2014-1202 | — | — | 7.7% | Jan 25, 2014 | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a c... |
| CVE-2014-1476 | — | — | 1.1% | Jan 24, 2014 | The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restri... |
| CVE-2014-1475 | — | — | 1.5% | Jan 24, 2014 | The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other user... |
| CVE-2014-1447 | — | — | 2.3% | Jan 24, 2014 | Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause... |
| CVE-2014-0028 | — | — | 0.6% | Jan 24, 2014 | libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains r... |
| CVE-2014-1252 | — | — | 4.2% | Jan 24, 2014 | Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary ... |
| CVE-2014-0809 | — | — | 1.5% | Jan 24, 2014 | Directory traversal vulnerability in the Gapless Player SimZip (aka Simple Zip Viewer) application before 1.2.1 for Andr... |
| CVE-2014-0674 | — | — | 1.6% | Jan 24, 2014 | Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which... |
| CVE-2014-1242 | — | — | 1.0% | Jan 23, 2014 | Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof ... |
| CVE-2014-0494 | — | — | 4.8% | Jan 23, 2014 | Adobe Digital Editions 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption ... |
| CVE-2014-0675 | — | — | 1.6% | Jan 23, 2014 | The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate ... |
| CVE-2014-0979 | — | — | 0.4% | Jan 23, 2014 | The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle... |
| CVE-2014-0006 | — | — | 1.9% | Jan 23, 2014 | The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows ... |
| CVE-2014-0808 | CRITICAL | 9.1 | 2.2% | Jan 22, 2014 | Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems dep... |
| CVE-2014-0807 | — | — | 1.6% | Jan 22, 2014 | data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, all... |
| CVE-2014-0806 | — | — | 1.1% | Jan 22, 2014 | The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for ... |
| CVE-2014-0677 | — | — | 2.1% | Jan 22, 2014 | The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service ... |
| CVE-2014-0676 | — | — | 0.4% | Jan 22, 2014 | Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bu... |
| CVE-2014-0662 | — | — | 1.9% | Jan 22, 2014 | The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a deni... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now