2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6616 | — | — | 1.9% | Aug 31, 2015 | Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS Single Channel (FG-100-PB) with firmware FG-x00-PB_V... |
| CVE-2014-3148 | — | — | 1.9% | Aug 31, 2015 | Cross-site scripting (XSS) vulnerability in libahttp/err.c in OkCupid OKWS (OK Web Server) allows remote attackers to in... |
| CVE-2014-2570 | — | — | 2.1% | Aug 31, 2015 | Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP Font Lib before 0.3.1 allows remote attackers to ... |
| CVE-2014-2332 | — | — | 1.4% | Aug 31, 2015 | Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a requ... |
| CVE-2014-2331 | — | — | 2.1% | Aug 31, 2015 | Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted ... |
| CVE-2014-2330 | — | — | 1.1% | Aug 31, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote ... |
| CVE-2014-2329 | — | — | 1.1% | Aug 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote au... |
| CVE-2014-9731 | — | — | 0.4% | Aug 31, 2015 | The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing ... |
| CVE-2014-9730 | — | — | 0.4% | Aug 31, 2015 | The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are u... |
| CVE-2014-9729 | — | — | 0.4% | Aug 31, 2015 | The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.18.2 does not ensure a certain data-structure... |
| CVE-2014-9728 | — | — | 0.5% | Aug 31, 2015 | The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows loca... |
| CVE-2014-9651 | — | — | 1.5% | Aug 28, 2015 | Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecifi... |
| CVE-2014-9744 | — | — | 2.0% | Aug 24, 2015 | Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a lar... |
| CVE-2014-8987 | — | — | 1.2% | Aug 24, 2015 | Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_rep... |
| CVE-2014-8628 | — | — | 1.7% | Aug 24, 2015 | Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memor... |
| CVE-2014-6272 | — | — | 2.1% | Aug 24, 2015 | Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.... |
| CVE-2014-3612 | — | — | 7.4% | Aug 24, 2015 | The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x be... |
| CVE-2014-1972 | — | — | 9.6% | Aug 22, 2015 | Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an obje... |
| CVE-2014-9743 | — | — | 1.9% | Aug 17, 2015 | Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in Vide... |
| CVE-2014-8155 | — | — | 1.0% | Aug 14, 2015 | GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-mid... |
| CVE-2014-3576 | — | — | 12.8% | Aug 14, 2015 | The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote att... |
| CVE-2014-9736 | — | — | 1.6% | Aug 4, 2015 | GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key ... |
| CVE-2014-7234 | — | — | — | Aug 4, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7233. Reason: This issue was MERGED into CVE-201... |
| CVE-2014-7233 | — | — | 1.7% | Aug 4, 2015 | GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2... |
| CVE-2014-7232 | — | — | 1.7% | Aug 4, 2015 | GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser u... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now