2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6139 | — | — | 1.0% | Feb 13, 2015 | The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to b... |
| CVE-2014-4813 | — | — | 0.3% | Feb 13, 2015 | Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0... |
| CVE-2014-4803 | — | — | 0.8% | Feb 13, 2015 | CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 befor... |
| CVE-2014-4781 | — | — | 1.2% | Feb 13, 2015 | The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive ... |
| CVE-2014-4771 | — | — | 1.6% | Feb 13, 2015 | IBM WebSphere MQ 7.0.1 before 7.0.1.13, 7.1 before 7.1.0.6, 7.5 before 7.5.0.5, and 8 before 8.0.0.1 allows remote authe... |
| CVE-2014-9512 | — | — | 6.5% | Feb 12, 2015 | rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization pa... |
| CVE-2014-8110 | — | — | 7.1% | Feb 12, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x befor... |
| CVE-2014-3365 | — | — | 1.8% | Feb 12, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow r... |
| CVE-2014-2153 | — | — | 1.8% | Feb 12, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers... |
| CVE-2014-2152 | — | — | 1.0% | Feb 12, 2015 | Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote atta... |
| CVE-2014-2147 | — | — | 1.5% | Feb 12, 2015 | The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which... |
| CVE-2014-6362 | — | — | 16.2% | Feb 11, 2015 | Use-after-free vulnerability in Microsoft Office 2007 SP3, 2010 SP2, and 2013 Gold and SP1 allows remote attackers to by... |
| CVE-2014-8733 | — | — | 0.3% | Feb 10, 2015 | Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files ... |
| CVE-2014-8614 | — | — | — | Feb 9, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-8615 | — | — | — | Feb 9, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-9675 | — | — | 4.2% | Feb 8, 2015 | bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, ... |
| CVE-2014-9674 | — | — | 5.7% | Feb 8, 2015 | The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values with... |
| CVE-2014-9673 | — | — | 3.4% | Feb 8, 2015 | Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote ... |
| CVE-2014-9672 | — | — | 4.7% | Feb 8, 2015 | Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a... |
| CVE-2014-9671 | — | — | 3.5% | Feb 8, 2015 | Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to... |
| CVE-2014-9670 | — | — | 4.2% | Feb 8, 2015 | Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow rem... |
| CVE-2014-9669 | — | — | 3.9% | Feb 8, 2015 | Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service... |
| CVE-2014-9668 | — | — | 1.9% | Feb 8, 2015 | The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without r... |
| CVE-2014-9667 | — | — | 3.5% | Feb 8, 2015 | sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which al... |
| CVE-2014-9666 | — | — | 4.2% | Feb 8, 2015 | The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association wi... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now