2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9198 | — | — | 4.2% | Jan 27, 2015 | The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded ... |
| CVE-2014-9197 | — | — | 2.0% | Jan 27, 2015 | The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root... |
| CVE-2014-9573 | — | — | 1.4% | Jan 26, 2015 | SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remot... |
| CVE-2014-9572 | — | — | 2.5% | Jan 26, 2015 | MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows r... |
| CVE-2014-9571 | — | — | 2.2% | Jan 26, 2015 | Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 al... |
| CVE-2014-8158 | — | — | 14.4% | Jan 26, 2015 | Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a deni... |
| CVE-2014-8157 | — | — | 16.9% | Jan 26, 2015 | Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a de... |
| CVE-2014-8148 | — | — | 0.4% | Jan 26, 2015 | The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals... |
| CVE-2014-9640 | — | — | 3.2% | Jan 23, 2015 | oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a cr... |
| CVE-2014-9639 | — | — | 3.6% | Jan 23, 2015 | Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a craf... |
| CVE-2014-9638 | — | — | 3.6% | Jan 23, 2015 | oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a... |
| CVE-2014-9623 | — | — | 2.8% | Jan 23, 2015 | OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storag... |
| CVE-2014-8802 | — | — | 7.8% | Jan 23, 2015 | The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-regist... |
| CVE-2014-7948 | — | — | 1.4% | Jan 22, 2015 | The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Goog... |
| CVE-2014-7947 | — | — | 1.7% | Jan 22, 2015 | OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial... |
| CVE-2014-7946 | — | — | 1.6% | Jan 22, 2015 | The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrom... |
| CVE-2014-7945 | — | — | 1.8% | Jan 22, 2015 | OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial... |
| CVE-2014-7944 | — | — | 1.9% | Jan 22, 2015 | The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.9... |
| CVE-2014-7943 | — | — | 1.6% | Jan 22, 2015 | Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds ... |
| CVE-2014-7942 | — | — | 1.6% | Jan 22, 2015 | The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which all... |
| CVE-2014-7941 | — | — | 1.6% | Jan 22, 2015 | The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome bef... |
| CVE-2014-7940 | — | — | 2.1% | Jan 22, 2015 | The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 29312... |
| CVE-2014-7939 | — | — | 2.6% | Jan 22, 2015 | Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the... |
| CVE-2014-7938 | — | — | 1.6% | Jan 22, 2015 | The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memo... |
| CVE-2014-7937 | — | — | 1.8% | Jan 22, 2015 | Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.9... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now