2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2152 | — | — | 1.0% | Feb 12, 2015 | Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote atta... |
| CVE-2014-2147 | — | — | 1.5% | Feb 12, 2015 | The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which... |
| CVE-2014-6362 | — | — | 16.2% | Feb 11, 2015 | Use-after-free vulnerability in Microsoft Office 2007 SP3, 2010 SP2, and 2013 Gold and SP1 allows remote attackers to by... |
| CVE-2014-8733 | — | — | 0.3% | Feb 10, 2015 | Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files ... |
| CVE-2014-8615 | — | — | — | Feb 9, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-8614 | — | — | — | Feb 9, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-9675 | — | — | 4.2% | Feb 8, 2015 | bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, ... |
| CVE-2014-9674 | — | — | 5.7% | Feb 8, 2015 | The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values with... |
| CVE-2014-9673 | — | — | 3.4% | Feb 8, 2015 | Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote ... |
| CVE-2014-9672 | — | — | 4.7% | Feb 8, 2015 | Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a... |
| CVE-2014-9671 | — | — | 3.5% | Feb 8, 2015 | Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to... |
| CVE-2014-9670 | — | — | 4.2% | Feb 8, 2015 | Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow rem... |
| CVE-2014-9669 | — | — | 3.9% | Feb 8, 2015 | Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service... |
| CVE-2014-9668 | — | — | 1.9% | Feb 8, 2015 | The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without r... |
| CVE-2014-9667 | — | — | 3.5% | Feb 8, 2015 | sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which al... |
| CVE-2014-9666 | — | — | 4.2% | Feb 8, 2015 | The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association wi... |
| CVE-2014-9665 | — | — | 4.9% | Feb 8, 2015 | The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG... |
| CVE-2014-9664 | — | — | 4.3% | Feb 8, 2015 | FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attacke... |
| CVE-2014-9663 | — | — | 5.1% | Feb 8, 2015 | The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that fi... |
| CVE-2014-9662 | — | — | 4.3% | Feb 8, 2015 | cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows rem... |
| CVE-2014-9661 | — | — | 4.4% | Feb 8, 2015 | type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error... |
| CVE-2014-9660 | — | — | 5.1% | Feb 8, 2015 | The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR recor... |
| CVE-2014-9659 | — | — | 7.7% | Feb 8, 2015 | cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint ... |
| CVE-2014-9658 | — | — | 5.1% | Feb 8, 2015 | The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, whi... |
| CVE-2014-9657 | — | — | 5.1% | Feb 8, 2015 | The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now