2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9728 | — | — | 0.5% | Aug 31, 2015 | The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows loca... |
| CVE-2014-9651 | — | — | 1.5% | Aug 28, 2015 | Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecifi... |
| CVE-2014-9744 | — | — | 2.0% | Aug 24, 2015 | Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a lar... |
| CVE-2014-8987 | — | — | 1.2% | Aug 24, 2015 | Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_rep... |
| CVE-2014-8628 | — | — | 1.7% | Aug 24, 2015 | Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memor... |
| CVE-2014-6272 | — | — | 2.1% | Aug 24, 2015 | Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.... |
| CVE-2014-3612 | — | — | 7.4% | Aug 24, 2015 | The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x be... |
| CVE-2014-1972 | — | — | 9.6% | Aug 22, 2015 | Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an obje... |
| CVE-2014-9743 | — | — | 1.9% | Aug 17, 2015 | Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in Vide... |
| CVE-2014-8155 | — | — | 1.0% | Aug 14, 2015 | GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-mid... |
| CVE-2014-3576 | — | — | 12.8% | Aug 14, 2015 | The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote att... |
| CVE-2014-9736 | — | — | 1.6% | Aug 4, 2015 | GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key ... |
| CVE-2014-7234 | — | — | — | Aug 4, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7233. Reason: This issue was MERGED into CVE-201... |
| CVE-2014-7233 | — | — | 1.7% | Aug 4, 2015 | GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2... |
| CVE-2014-7232 | — | — | 1.7% | Aug 4, 2015 | GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser u... |
| CVE-2014-7913 | — | — | 1.8% | Jul 30, 2015 | The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android before 5.... |
| CVE-2014-7912 | — | — | 2.7% | Jul 30, 2015 | The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products... |
| CVE-2014-0611 | — | — | 2.3% | Jul 22, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014... |
| CVE-2014-9196 | — | — | 2.3% | Jul 20, 2015 | Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates T... |
| CVE-2014-8910 | — | — | 1.9% | Jul 20, 2015 | IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remo... |
| CVE-2014-8450 | — | — | 4.6% | Jul 15, 2015 | Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.... |
| CVE-2014-0578 | — | — | 3.6% | Jul 9, 2015 | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481... |
| CVE-2014-9741 | — | — | 1.8% | Jul 8, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server... |
| CVE-2014-8175 | — | — | 1.5% | Jul 8, 2015 | Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO ... |
| CVE-2014-5406 | — | — | 1.2% | Jul 6, 2015 | The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now