2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-7882Unspecified vulnerability in HP SiteScope 11.1x and 11.2x allows remote authenticated users to gain privileges via unkno...
CVE-2014-6170The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0...
CVE-2014-6141IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 be...
CVE-2014-6136IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attacker...
CVE-2014-9200Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachi...
CVE-2014-8630Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote...
CVE-2014-7270Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlie...
CVE-2014-7269ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 ...
CVE-2014-7266Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote ...
CVE-2014-8268QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request.
CVE-2014-8267Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary ...
CVE-2014-8266Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow r...
CVE-2014-7288Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator...
CVE-2014-7287The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows r...
CVE-2014-4632VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data...
CVE-2014-9161CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.1...
CVE-2014-8840The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mecha...
CVE-2014-8839Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which ...
CVE-2014-8838The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates,...
CVE-2014-8837Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arb...
CVE-2014-8836The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or ...
CVE-2014-8835The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke...
CVE-2014-8834UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, wh...
CVE-2014-8833SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cach...
CVE-2014-8832The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, w...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now