2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8617 | — | — | 1.2% | Mar 4, 2015 | Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMai... |
| CVE-2014-9683 | — | — | 0.4% | Mar 3, 2015 | Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the ... |
| CVE-2014-9283 | — | — | 2.4% | Mar 3, 2015 | The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mecha... |
| CVE-2014-7896 | — | — | 2.5% | Mar 3, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, a... |
| CVE-2014-9644 | — | — | 0.5% | Mar 2, 2015 | The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system c... |
| CVE-2014-8160 | — | — | 5.5% | Mar 2, 2015 | net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during ... |
| CVE-2014-8921 | — | — | 1.8% | Mar 2, 2015 | The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Not... |
| CVE-2014-9682 | — | — | 2.9% | Feb 28, 2015 | The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell ... |
| CVE-2014-9676 | — | — | 3.3% | Feb 28, 2015 | The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory loca... |
| CVE-2014-2188 | — | — | — | Feb 27, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-0607. Reason: This candidate is a duplicate of... |
| CVE-2014-9685 | — | — | 1.8% | Feb 25, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remo... |
| CVE-2014-9282 | — | — | 1.6% | Feb 24, 2015 | Directory traversal vulnerability in the Speed Root Explorer application before 3.2 for Android and the Speed Explorer a... |
| CVE-2014-6115 | — | — | 1.3% | Feb 24, 2015 | IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a cra... |
| CVE-2014-4818 | — | — | 0.2% | Feb 24, 2015 | dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows l... |
| CVE-2014-9684 | — | — | 2.0% | Feb 24, 2015 | OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which al... |
| CVE-2014-9402 | — | — | 7.7% | Feb 24, 2015 | The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Se... |
| CVE-2014-8487 | — | — | 1.0% | Feb 24, 2015 | Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) ... |
| CVE-2014-7922 | — | — | 0.5% | Feb 23, 2015 | The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests u... |
| CVE-2014-6184 | — | — | 0.4% | Feb 22, 2015 | Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through... |
| CVE-2014-8115 | — | — | 1.9% | Feb 20, 2015 | The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitr... |
| CVE-2014-8114 | — | — | 3.1% | Feb 20, 2015 | The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary co... |
| CVE-2014-3682 | — | — | 2.9% | Feb 20, 2015 | XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2Resour... |
| CVE-2014-0005 | — | — | 0.8% | Feb 20, 2015 | PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.... |
| CVE-2014-5355 | — | — | 4.6% | Feb 20, 2015 | MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a str... |
| CVE-2014-3578 | — | — | 6.2% | Feb 19, 2015 | Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attack... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now