2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9665——The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG...
CVE-2014-9664——FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attacke...
CVE-2014-9663——The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that fi...
CVE-2014-9662——cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows rem...
CVE-2014-9661——type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error...
CVE-2014-9660——The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR recor...
CVE-2014-9659——cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint ...
CVE-2014-9658——The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, whi...
CVE-2014-9657——The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, ...
CVE-2014-9656——The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer...
CVE-2014-9203——Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used ...
CVE-2014-9643——K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users...
CVE-2014-9642——bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows loca...
CVE-2014-9641——The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo...
CVE-2014-9636——unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra fiel...
CVE-2014-9632——The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec...
CVE-2014-9354——NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related...
CVE-2014-9353——NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain pri...
CVE-2014-5332——Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 allows local users to gain privileges via a crafted NVMAP_IOC_...
CVE-2014-0606——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0603. Reason: This issue was MERGED into CVE-201...
CVE-2014-0605——Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429...
CVE-2014-0604——Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429...
CVE-2014-0603——The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a d...
CVE-2014-9562——Cross-site scripting (XSS) vulnerability in display_dialog.php in M2 OptimalSite 0.1 and 2.4 allows remote attackers to ...
CVE-2014-9049——The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now