2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-2209——Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capabi...
CVE-2014-2208——CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipH...
CVE-2014-9188——Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers...
CVE-2014-8514——Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers...
CVE-2014-8513——Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers...
CVE-2014-8512——Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers t...
CVE-2014-8511——Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers t...
CVE-2014-0748——apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID i...
CVE-2014-9420——The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock Ri...
CVE-2014-9419——The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread ...
CVE-2014-7300——GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption ...
CVE-2014-2217——Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX be...
CVE-2014-1449——The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via...
CVE-2014-7193——The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handl...
CVE-2014-3971——The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x be...
CVE-2014-9418——The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users...
CVE-2014-9417——The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (progr...
CVE-2014-9416——Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute ...
CVE-2014-9415——Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QE...
CVE-2014-9414——The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attack...
CVE-2014-9413——Multiple cross-site request forgery (CSRF) vulnerabilities in the IP Ban (simple-ip-ban) plugin 1.2.3 for WordPress allo...
CVE-2014-9334——Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote at...
CVE-2014-9223——Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and product...
CVE-2014-9222——AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re...
CVE-2014-8810——SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now