2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9728The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows loca...
CVE-2014-9651Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecifi...
CVE-2014-9744Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a lar...
CVE-2014-8987Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_rep...
CVE-2014-8628Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memor...
CVE-2014-6272Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2....
CVE-2014-3612The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x be...
CVE-2014-1972Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an obje...
CVE-2014-9743Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in Vide...
CVE-2014-8155GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-mid...
CVE-2014-3576The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote att...
CVE-2014-9736GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key ...
CVE-2014-7234Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7233. Reason: This issue was MERGED into CVE-201...
CVE-2014-7233GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2...
CVE-2014-7232GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser u...
CVE-2014-7913The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android before 5....
CVE-2014-7912The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products...
CVE-2014-0611Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014...
CVE-2014-9196Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates T...
CVE-2014-8910IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remo...
CVE-2014-8450Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015....
CVE-2014-0578Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481...
CVE-2014-9741Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server...
CVE-2014-8175Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO ...
CVE-2014-5406The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now