2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3687 | HIGH | 7.5 | 8.6% | Nov 10, 2014 | The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through... |
| CVE-2014-3673 | HIGH | 7.5 | 7.5% | Nov 10, 2014 | The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system ... |
| CVE-2014-4627 | HIGH | 8.8 | 2.3% | Nov 7, 2014 | SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to exec... |
| CVE-2014-6352 | HIGH | 7.8 | 77.6% | Oct 22, 2014 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2... |
| CVE-2014-4148 | HIGH | 8.8 | 50.7% | Oct 15, 2014 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2014-4123 | HIGH | 8.8 | 40.3% | Oct 15, 2014 | Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Interne... |
| CVE-2014-4114 | HIGH | 7.8 | 81.6% | Oct 15, 2014 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2... |
| CVE-2014-4113 | HIGH | 7.8 | 87.0% | Oct 15, 2014 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2014-6278 | HIGH | 8.8 | 99.6% | Sep 30, 2014 | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi... |
| CVE-2014-4404 | HIGH | 7.8 | 49.0% | Sep 18, 2014 | Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr... |
| CVE-2014-2817 | HIGH | 8.8 | 26.3% | Aug 12, 2014 | Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Interne... |
| CVE-2014-2815 | HIGH | 8.8 | 43.8% | Aug 12, 2014 | Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers cr... |
| CVE-2014-3120 | HIGH | 8.1 | 88.6% | Jul 28, 2014 | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut... |
| CVE-2014-4608 | HIGH | 7.3 | 5.4% | Jul 3, 2014 | Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompres... |
| CVE-2014-3153 | HIGH | 7.8 | 37.2% | Jun 7, 2014 | The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff... |
| CVE-2014-0224 | HIGH | 7.4 | 95.3% | Jun 5, 2014 | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph... |
| CVE-2014-1745 | HIGH | 7.1 | 1.7% | May 21, 2014 | Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows r... |
| CVE-2014-1812 | HIGH | 8.8 | 64.3% | May 14, 2014 | The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo... |
| CVE-2014-0130 | HIGH | 7.5 | 53.7% | May 7, 2014 | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in... |
| CVE-2014-1531 | HIGH | 8.8 | 5.6% | Apr 30, 2014 | Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0... |
| CVE-2014-1529 | HIGH | 8.8 | 3.7% | Apr 30, 2014 | The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaM... |
| CVE-2014-1518 | HIGH | 8.8 | 6.0% | Apr 30, 2014 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5,... |
| CVE-2014-0160 | HIGH | 7.5 | 100.0% | Apr 7, 2014 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe... |
| CVE-2014-1761 | HIGH | 7.8 | 77.7% | Mar 25, 2014 | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi... |
| CVE-2014-1513 | HIGH | 8.8 | 5.6% | Mar 19, 2014 | TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonke... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now