2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8268 | — | — | 1.3% | Feb 1, 2015 | QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request. |
| CVE-2014-8267 | — | — | 1.1% | Feb 1, 2015 | Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary ... |
| CVE-2014-8266 | — | — | 1.7% | Feb 1, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow r... |
| CVE-2014-7288 | — | — | 8.1% | Feb 1, 2015 | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator... |
| CVE-2014-7287 | — | — | 1.1% | Feb 1, 2015 | The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows r... |
| CVE-2014-4632 | — | — | 0.6% | Feb 1, 2015 | VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data... |
| CVE-2014-9161 | — | — | 4.1% | Jan 30, 2015 | CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.1... |
| CVE-2014-8840 | — | — | 2.2% | Jan 30, 2015 | The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mecha... |
| CVE-2014-8839 | — | — | 2.1% | Jan 30, 2015 | Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which ... |
| CVE-2014-8838 | — | — | 0.9% | Jan 30, 2015 | The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates,... |
| CVE-2014-8837 | — | — | 2.6% | Jan 30, 2015 | Multiple unspecified vulnerabilities in the Bluetooth driver in Apple OS X before 10.10.2 allow attackers to execute arb... |
| CVE-2014-8836 | — | — | 3.4% | Jan 30, 2015 | The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or ... |
| CVE-2014-8835 | — | — | 8.3% | Jan 30, 2015 | The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke... |
| CVE-2014-8834 | — | — | 0.4% | Jan 30, 2015 | UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, wh... |
| CVE-2014-8833 | — | — | 0.3% | Jan 30, 2015 | SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cach... |
| CVE-2014-8832 | — | — | 0.4% | Jan 30, 2015 | The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, w... |
| CVE-2014-8831 | — | — | 0.9% | Jan 30, 2015 | security_taskgate in Apple OS X before 10.10.2 allows attackers to read group-ACL-restricted keychain items of arbitrary... |
| CVE-2014-8830 | — | — | 3.8% | Jan 30, 2015 | Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or... |
| CVE-2014-8829 | — | — | 2.4% | Jan 30, 2015 | SceneKit in Apple OS X before 10.10.2 allows attackers to execute arbitrary code or cause a denial of service (out-of-bo... |
| CVE-2014-8828 | — | — | 1.7% | Jan 30, 2015 | Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that inclu... |
| CVE-2014-8827 | — | — | 0.4% | Jan 30, 2015 | LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from ... |
| CVE-2014-8826 | — | — | 8.7% | Jan 30, 2015 | LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas... |
| CVE-2014-8825 | — | — | 0.4% | Jan 30, 2015 | The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service fu... |
| CVE-2014-8824 | — | — | 2.9% | Jan 30, 2015 | The kernel in Apple OS X before 10.10.2 does not properly validate IODataQueue object metadata fields, which allows atta... |
| CVE-2014-8823 | — | — | 0.4% | Jan 30, 2015 | The IOUSBControllerUserClient::ReadRegister function in the IOUSB controller in IOUSBFamily in Apple OS X before 10.10.2... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now