2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7888 | — | — | 10.3% | Mar 9, 2015 | The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute a... |
| CVE-2014-9472 | — | — | 2.8% | Mar 9, 2015 | The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote atta... |
| CVE-2014-3691 | — | — | 1.7% | Mar 9, 2015 | Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL cer... |
| CVE-2014-9689 | — | — | 1.3% | Mar 9, 2015 | content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly ... |
| CVE-2014-9369 | — | — | 2.3% | Mar 7, 2015 | Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (... |
| CVE-2014-8892 | — | — | 4.5% | Mar 6, 2015 | Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 b... |
| CVE-2014-8891 | — | — | 7.2% | Mar 6, 2015 | Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 b... |
| CVE-2014-2130 | — | — | 4.0% | Mar 6, 2015 | Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, ... |
| CVE-2014-9688 | — | — | 2.0% | Mar 5, 2015 | Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vec... |
| CVE-2014-8617 | — | — | 1.2% | Mar 4, 2015 | Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMai... |
| CVE-2014-9683 | — | — | 0.4% | Mar 3, 2015 | Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the ... |
| CVE-2014-9283 | — | — | 2.4% | Mar 3, 2015 | The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mecha... |
| CVE-2014-7896 | — | — | 2.5% | Mar 3, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, a... |
| CVE-2014-9644 | — | — | 0.5% | Mar 2, 2015 | The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system c... |
| CVE-2014-8160 | — | — | 5.5% | Mar 2, 2015 | net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during ... |
| CVE-2014-8921 | — | — | 1.8% | Mar 2, 2015 | The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Not... |
| CVE-2014-9682 | — | — | 2.9% | Feb 28, 2015 | The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell ... |
| CVE-2014-9676 | — | — | 3.3% | Feb 28, 2015 | The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory loca... |
| CVE-2014-2188 | — | — | — | Feb 27, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-0607. Reason: This candidate is a duplicate of... |
| CVE-2014-9685 | — | — | 1.8% | Feb 25, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remo... |
| CVE-2014-9282 | — | — | 1.6% | Feb 24, 2015 | Directory traversal vulnerability in the Speed Root Explorer application before 3.2 for Android and the Speed Explorer a... |
| CVE-2014-6115 | — | — | 1.3% | Feb 24, 2015 | IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a cra... |
| CVE-2014-4818 | — | — | 0.2% | Feb 24, 2015 | dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows l... |
| CVE-2014-9684 | — | — | 2.0% | Feb 24, 2015 | OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which al... |
| CVE-2014-9402 | — | — | 7.7% | Feb 24, 2015 | The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Se... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now