2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0230 | — | — | 20.3% | Jun 7, 2015 | Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP re... |
| CVE-2014-8887 | — | — | 1.1% | Jun 7, 2015 | IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.... |
| CVE-2014-6222 | — | — | 1.5% | Jun 7, 2015 | Directory traversal vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x ... |
| CVE-2014-6175 | — | — | 1.0% | Jun 7, 2015 | Cross-site scripting (XSS) vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8,... |
| CVE-2014-9201 | — | — | 1.6% | Jun 5, 2015 | Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage... |
| CVE-2014-9721 | — | — | 2.5% | Jun 3, 2015 | libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 proto... |
| CVE-2014-8391 | — | — | 5.5% | Jun 2, 2015 | The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o... |
| CVE-2014-0999 | — | — | 6.7% | Jun 2, 2015 | Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive... |
| CVE-2014-9727 | — | — | 71.6% | May 29, 2015 | AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter t... |
| CVE-2014-6628 | — | — | 1.6% | May 28, 2015 | Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via u... |
| CVE-2014-9715 | — | — | 0.4% | May 27, 2015 | include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insuffi... |
| CVE-2014-9710 | — | — | 0.3% | May 27, 2015 | The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with... |
| CVE-2014-8147 | — | — | 23.2% | May 25, 2015 | The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in I... |
| CVE-2014-8146 | — | — | 24.3% | May 25, 2015 | The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in I... |
| CVE-2014-8927 | — | — | 1.3% | May 25, 2015 | Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for So... |
| CVE-2014-8926 | — | — | 1.3% | May 25, 2015 | Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for So... |
| CVE-2014-6192 | — | — | 0.8% | May 25, 2015 | Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.... |
| CVE-2014-6190 | — | — | 1.2% | May 25, 2015 | The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a... |
| CVE-2014-4778 | — | — | 1.0% | May 25, 2015 | IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an ... |
| CVE-2014-4774 | — | — | 0.6% | May 25, 2015 | Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoi... |
| CVE-2014-2174 | — | — | 1.0% | May 25, 2015 | Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which al... |
| CVE-2014-8924 | — | — | 1.8% | May 20, 2015 | The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7... |
| CVE-2014-4776 | — | — | 0.7% | May 20, 2015 | IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which ma... |
| CVE-2014-6211 | — | — | 0.4% | May 20, 2015 | The command-line scripts in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 2 thr... |
| CVE-2014-3685 | — | — | — | May 19, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now