2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2014-3687HIGH7.5The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through...
CVE-2014-3673HIGH7.5The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system ...
CVE-2014-4627HIGH8.8SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to exec...
CVE-2014-6352HIGH7.8Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2...
CVE-2014-4148HIGH8.8win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a...
CVE-2014-4123HIGH8.8Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Interne...
CVE-2014-4114HIGH7.8Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2...
CVE-2014-4113HIGH7.8win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a...
CVE-2014-6278HIGH8.8GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi...
CVE-2014-4404HIGH7.8Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr...
CVE-2014-2817HIGH8.8Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Interne...
CVE-2014-2815HIGH8.8Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers cr...
CVE-2014-3120HIGH8.1The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut...
CVE-2014-4608HIGH7.3Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompres...
CVE-2014-3153HIGH7.8The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff...
CVE-2014-0224HIGH7.4OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph...
CVE-2014-1745HIGH7.1Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows r...
CVE-2014-1812HIGH8.8The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo...
CVE-2014-0130HIGH7.5Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in...
CVE-2014-1531HIGH8.8Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0...
CVE-2014-1529HIGH8.8The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaM...
CVE-2014-1518HIGH8.8Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5,...
CVE-2014-0160HIGH7.5The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe...
CVE-2014-1761HIGH7.8Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi...
CVE-2014-1513HIGH8.8TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonke...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now