2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9411 | — | — | 0.8% | Aug 18, 2017 | In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offse... |
| CVE-2014-3451 | — | — | 1.8% | Aug 18, 2017 | OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified ... |
| CVE-2014-0146 | — | — | 0.4% | Aug 10, 2017 | The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a d... |
| CVE-2014-0145 | — | — | 0.5% | Aug 10, 2017 | Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (cra... |
| CVE-2014-0143 | — | — | 0.4% | Aug 10, 2017 | Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of s... |
| CVE-2014-0142 | — | — | 0.4% | Aug 10, 2017 | QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero... |
| CVE-2014-9701 | — | — | 2.3% | Aug 9, 2017 | Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers... |
| CVE-2014-6393 | — | — | 1.1% | Aug 9, 2017 | The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Ty... |
| CVE-2014-5144 | — | — | 2.0% | Aug 9, 2017 | Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary... |
| CVE-2014-9831 | HIGH | 8.8 | 1.9% | Aug 7, 2017 | coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file. |
| CVE-2014-9830 | HIGH | 8.8 | 1.9% | Aug 7, 2017 | coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file. |
| CVE-2014-9828 | HIGH | 8.8 | 2.0% | Aug 7, 2017 | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file. |
| CVE-2014-9827 | HIGH | 8.8 | 1.9% | Aug 7, 2017 | coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file. |
| CVE-2014-3462 | HIGH | 7.5 | 3.1% | Aug 7, 2017 | The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "... |
| CVE-2014-1235 | — | — | 2.9% | Aug 7, 2017 | Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary co... |
| CVE-2014-9262 | — | — | 7.5% | Aug 7, 2017 | The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. |
| CVE-2014-9260 | HIGH | 8.8 | 11.1% | Aug 7, 2017 | The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users ... |
| CVE-2014-8903 | — | — | 2.2% | Aug 2, 2017 | IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remo... |
| CVE-2014-8107 | — | — | — | Jul 20, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-10022. Reason: This candidate is a reservation... |
| CVE-2014-0052 | — | — | — | Jul 20, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-7954 | — | — | 0.4% | Jul 7, 2017 | Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4... |
| CVE-2014-7953 | — | — | 0.3% | Jul 7, 2017 | Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb ... |
| CVE-2014-8149 | — | — | — | Jun 27, 2017 | OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files. |
| CVE-2014-6354 | — | — | — | Jun 27, 2017 | Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet E... |
| CVE-2014-8127 | — | — | — | Jun 26, 2017 | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF ima... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now