2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9653 | — | — | 4.7% | Mar 30, 2015 | readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x be... |
| CVE-2014-9652 | — | — | 5.5% | Mar 30, 2015 | The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x ... |
| CVE-2014-9205 | — | — | 4.8% | Mar 29, 2015 | Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMO... |
| CVE-2014-5428 | — | — | 3.9% | Mar 29, 2015 | Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used ... |
| CVE-2014-5427 | — | — | 1.4% | Mar 29, 2015 | Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Se... |
| CVE-2014-9712 | — | — | 0.9% | Mar 27, 2015 | Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to rea... |
| CVE-2014-8121 | — | — | 6.4% | Mar 27, 2015 | DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earli... |
| CVE-2014-3619 | — | — | 2.7% | Mar 27, 2015 | The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinit... |
| CVE-2014-9711 | — | — | 2.5% | Mar 25, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 ... |
| CVE-2014-8925 | — | — | 0.9% | Mar 25, 2015 | Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.... |
| CVE-2014-8923 | — | — | 0.4% | Mar 25, 2015 | The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active ... |
| CVE-2014-6134 | — | — | 0.3% | Mar 25, 2015 | IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, r... |
| CVE-2014-9261 | — | — | 9.1% | Mar 23, 2015 | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which ... |
| CVE-2014-8169 | — | — | 0.3% | Mar 18, 2015 | automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environmen... |
| CVE-2014-6131 | — | — | 1.3% | Mar 18, 2015 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi... |
| CVE-2014-6129 | — | — | 1.4% | Mar 18, 2015 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi... |
| CVE-2014-9687 | — | — | 2.2% | Mar 16, 2015 | eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obt... |
| CVE-2014-8173 | — | — | 0.4% | Mar 16, 2015 | The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUM... |
| CVE-2014-8172 | — | — | 0.4% | Mar 16, 2015 | The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inap... |
| CVE-2014-8159 | — | — | 0.4% | Mar 16, 2015 | The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL)... |
| CVE-2014-7822 | — | — | 1.2% | Mar 16, 2015 | The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restrictio... |
| CVE-2014-9207 | — | — | 0.5% | Mar 14, 2015 | Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows l... |
| CVE-2014-9206 | — | — | 0.3% | Mar 14, 2015 | Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control V... |
| CVE-2014-7885 | — | — | 3.0% | Mar 14, 2015 | Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact an... |
| CVE-2014-7884 | — | — | 11.8% | Mar 14, 2015 | Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated att... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now