2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4477 | — | — | 2.8% | Jan 30, 2015 | WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple ... |
| CVE-2014-4476 | — | — | 2.8% | Jan 30, 2015 | WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple ... |
| CVE-2014-4467 | — | — | 1.1% | Jan 30, 2015 | WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAM... |
| CVE-2014-8370 | — | — | 4.2% | Jan 29, 2015 | VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5... |
| CVE-2014-8895 | — | — | 1.2% | Jan 29, 2015 | IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypa... |
| CVE-2014-8894 | — | — | 1.0% | Jan 29, 2015 | Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 ... |
| CVE-2014-8893 | — | — | 0.9% | Jan 29, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Appli... |
| CVE-2014-8920 | — | — | 0.4% | Jan 28, 2015 | Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to... |
| CVE-2014-8917 | — | — | 2.1% | Jan 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox... |
| CVE-2014-8154 | — | — | 2.8% | Jan 27, 2015 | The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer binding... |
| CVE-2014-5211 | — | — | 2.8% | Jan 27, 2015 | Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute... |
| CVE-2014-9650 | — | — | 2.6% | Jan 27, 2015 | CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attacke... |
| CVE-2014-9649 | — | — | 2.3% | Jan 27, 2015 | Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows re... |
| CVE-2014-9648 | — | — | 1.0% | Jan 27, 2015 | components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on And... |
| CVE-2014-9647 | — | — | 1.1% | Jan 27, 2015 | Use-after-free vulnerability in PDFium, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a... |
| CVE-2014-9646 | — | — | 0.3% | Jan 27, 2015 | Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in instal... |
| CVE-2014-9198 | — | — | 4.2% | Jan 27, 2015 | The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded ... |
| CVE-2014-9197 | — | — | 2.0% | Jan 27, 2015 | The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root... |
| CVE-2014-9573 | — | — | 1.4% | Jan 26, 2015 | SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remot... |
| CVE-2014-9572 | — | — | 2.5% | Jan 26, 2015 | MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows r... |
| CVE-2014-9571 | — | — | 2.2% | Jan 26, 2015 | Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 al... |
| CVE-2014-8158 | — | — | 14.4% | Jan 26, 2015 | Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a deni... |
| CVE-2014-8157 | — | — | 16.9% | Jan 26, 2015 | Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a de... |
| CVE-2014-8148 | — | — | 0.4% | Jan 26, 2015 | The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals... |
| CVE-2014-9640 | — | — | 3.2% | Jan 23, 2015 | oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a cr... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now