2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8151 | — | — | 1.1% | Jan 15, 2015 | The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the Darwi... |
| CVE-2014-8150 | — | — | 6.8% | Jan 15, 2015 | CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers... |
| CVE-2014-7957 | — | — | 1.2% | Jan 15, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote atta... |
| CVE-2014-7956 | — | — | 2.0% | Jan 15, 2015 | Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject a... |
| CVE-2014-7812 | — | — | 1.5% | Jan 15, 2015 | Cross-site scripting (XSS) vulnerability in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allows remote aut... |
| CVE-2014-7811 | — | — | 1.5% | Jan 15, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow ... |
| CVE-2014-0171 | — | — | 2.1% | Jan 15, 2015 | XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualizat... |
| CVE-2014-3314 | — | — | 1.1% | Jan 14, 2015 | Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof auth... |
| CVE-2014-8643 | — | — | 1.5% | Jan 14, 2015 | Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection... |
| CVE-2014-8642 | — | — | 1.6% | Jan 14, 2015 | Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whe... |
| CVE-2014-8641 | — | — | 4.2% | Jan 14, 2015 | Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, ... |
| CVE-2014-8640 | — | — | 2.4% | Jan 14, 2015 | The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefo... |
| CVE-2014-8639 | — | — | 1.9% | Jan 14, 2015 | Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not pro... |
| CVE-2014-8638 | — | — | 1.0% | Jan 14, 2015 | The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before... |
| CVE-2014-8637 | — | — | 2.2% | Jan 14, 2015 | Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows rem... |
| CVE-2014-8636 | — | — | 65.7% | Jan 14, 2015 | The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with ... |
| CVE-2014-8635 | — | — | 4.1% | Jan 14, 2015 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allo... |
| CVE-2014-8634 | — | — | 3.9% | Jan 14, 2015 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4,... |
| CVE-2014-5233 | — | — | 0.4% | Jan 14, 2015 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtSe... |
| CVE-2014-5232 | — | — | 0.4% | Jan 14, 2015 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-pass... |
| CVE-2014-5231 | — | — | 0.4% | Jan 14, 2015 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the pass... |
| CVE-2014-10038 | — | — | 2.3% | Jan 13, 2015 | SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitr... |
| CVE-2014-10037 | — | — | 19.4% | Jan 13, 2015 | Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a ..... |
| CVE-2014-10036 | — | — | 1.9% | Jan 13, 2015 | Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary we... |
| CVE-2014-10035 | — | — | 3.5% | Jan 13, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now