2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9665 | — | — | 4.9% | Feb 8, 2015 | The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG... |
| CVE-2014-9664 | — | — | 4.3% | Feb 8, 2015 | FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attacke... |
| CVE-2014-9663 | — | — | 5.1% | Feb 8, 2015 | The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that fi... |
| CVE-2014-9662 | — | — | 4.3% | Feb 8, 2015 | cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows rem... |
| CVE-2014-9661 | — | — | 4.4% | Feb 8, 2015 | type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error... |
| CVE-2014-9660 | — | — | 5.1% | Feb 8, 2015 | The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR recor... |
| CVE-2014-9659 | — | — | 7.7% | Feb 8, 2015 | cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint ... |
| CVE-2014-9658 | — | — | 5.1% | Feb 8, 2015 | The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, whi... |
| CVE-2014-9657 | — | — | 5.1% | Feb 8, 2015 | The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, ... |
| CVE-2014-9656 | — | — | 4.6% | Feb 8, 2015 | The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer... |
| CVE-2014-9203 | — | — | 1.8% | Feb 7, 2015 | Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used ... |
| CVE-2014-9643 | — | — | 1.0% | Feb 6, 2015 | K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users... |
| CVE-2014-9642 | — | — | 1.1% | Feb 6, 2015 | bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows loca... |
| CVE-2014-9641 | — | — | 1.0% | Feb 6, 2015 | The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo... |
| CVE-2014-9636 | — | — | 11.6% | Feb 6, 2015 | unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra fiel... |
| CVE-2014-9632 | — | — | 1.5% | Feb 6, 2015 | The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec... |
| CVE-2014-9354 | — | — | 1.0% | Feb 6, 2015 | NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related... |
| CVE-2014-9353 | — | — | 2.9% | Feb 6, 2015 | NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain pri... |
| CVE-2014-5332 | — | — | 0.4% | Feb 6, 2015 | Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 allows local users to gain privileges via a crafted NVMAP_IOC_... |
| CVE-2014-0606 | — | — | — | Feb 6, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0603. Reason: This issue was MERGED into CVE-201... |
| CVE-2014-0605 | — | — | 7.7% | Feb 6, 2015 | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429... |
| CVE-2014-0604 | — | — | 6.3% | Feb 6, 2015 | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429... |
| CVE-2014-0603 | — | — | 5.7% | Feb 6, 2015 | The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a d... |
| CVE-2014-9562 | — | — | 0.9% | Feb 4, 2015 | Cross-site scripting (XSS) vulnerability in display_dialog.php in M2 OptimalSite 0.1 and 2.4 allows remote attackers to ... |
| CVE-2014-9049 | — | — | 0.9% | Feb 4, 2015 | The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now