2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7882 | — | — | 2.0% | Feb 2, 2015 | Unspecified vulnerability in HP SiteScope 11.1x and 11.2x allows remote authenticated users to gain privileges via unkno... |
| CVE-2014-6170 | — | — | 1.4% | Feb 2, 2015 | The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0... |
| CVE-2014-6141 | — | — | 1.8% | Feb 2, 2015 | IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 be... |
| CVE-2014-6136 | — | — | 1.2% | Feb 2, 2015 | IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attacker... |
| CVE-2014-9200 | — | — | 5.6% | Feb 1, 2015 | Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachi... |
| CVE-2014-8630 | — | — | 2.0% | Feb 1, 2015 | Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote... |
| CVE-2014-7270 | — | — | 0.6% | Feb 1, 2015 | Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlie... |
| CVE-2014-7269 | — | — | 1.9% | Feb 1, 2015 | ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 ... |
| CVE-2014-7266 | — | — | 1.8% | Feb 1, 2015 | Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote ... |
| CVE-2014-8268 | — | — | 1.3% | Feb 1, 2015 | QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request. |
| CVE-2014-8267 | — | — | 1.1% | Feb 1, 2015 | Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary ... |
| CVE-2014-8266 | — | — | 1.7% | Feb 1, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow r... |
| CVE-2014-7288 | — | — | 8.1% | Feb 1, 2015 | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator... |
| CVE-2014-7287 | — | — | 1.1% | Feb 1, 2015 | The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows r... |
| CVE-2014-4632 | — | — | 0.6% | Feb 1, 2015 | VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data... |
| CVE-2014-9161 | — | — | 4.1% | Jan 30, 2015 | CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.1... |
| CVE-2014-8840 | — | — | 2.2% | Jan 30, 2015 | The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mecha... |
| CVE-2014-8839 | — | — | 2.1% | Jan 30, 2015 | Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which ... |
| CVE-2014-8838 | — | — | 0.9% | Jan 30, 2015 | The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates,... |
| CVE-2014-8837 | — | — | 2.6% | Jan 30, 2015 | Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arb... |
| CVE-2014-8836 | — | — | 3.4% | Jan 30, 2015 | The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or ... |
| CVE-2014-8835 | — | — | 8.3% | Jan 30, 2015 | The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke... |
| CVE-2014-8834 | — | — | 0.4% | Jan 30, 2015 | UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, wh... |
| CVE-2014-8833 | — | — | 0.3% | Jan 30, 2015 | SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cach... |
| CVE-2014-8832 | — | — | 0.4% | Jan 30, 2015 | The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, w... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now