2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9656——The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer...
CVE-2014-9203——Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used ...
CVE-2014-9643——K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users...
CVE-2014-9642——bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows loca...
CVE-2014-9641——The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo...
CVE-2014-9636——unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra fiel...
CVE-2014-9632——The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec...
CVE-2014-9354——NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related...
CVE-2014-9353——NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain pri...
CVE-2014-5332——Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 allows local users to gain privileges via a crafted NVMAP_IOC_...
CVE-2014-0606——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0603. Reason: This issue was MERGED into CVE-201...
CVE-2014-0605——Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429...
CVE-2014-0604——Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429...
CVE-2014-0603——The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a d...
CVE-2014-9562——Cross-site scripting (XSS) vulnerability in display_dialog.php in M2 OptimalSite 0.1 and 2.4 allows remote attackers to ...
CVE-2014-9049——The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to ...
CVE-2014-9048——The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the...
CVE-2014-9047——Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x before 6.0.6 and 7.x before 7.0.3 allow remot...
CVE-2014-9046——The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remo...
CVE-2014-9045——The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass...
CVE-2014-9044——Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files...
CVE-2014-9043——The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before ...
CVE-2014-9042——Cross-site scripting (XSS) vulnerability in the import functionality in the bookmarks application in ownCloud before 5.0...
CVE-2014-9041——The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before...
CVE-2014-5341——The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now