2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9135 | — | — | 0.8% | Dec 19, 2014 | The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows remote attackers to spoof the ori... |
| CVE-2014-8875 | — | — | 2.6% | Dec 19, 2014 | The XML_RPC_cd function in lib/pear/XML/RPC.php in Revive Adserver before 3.0.6 allows remote attackers to cause a denia... |
| CVE-2014-8793 | — | — | 2.3% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in lib/max/Admin/UI/Field/PublisherIdField.php in Revive Adserver before 3.0.6 ... |
| CVE-2014-8724 | — | — | 2.1% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is e... |
| CVE-2014-8136 | — | — | 0.4% | Dec 19, 2014 | The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlo... |
| CVE-2014-8135 | — | — | 0.5% | Dec 19, 2014 | The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value... |
| CVE-2014-7208 | — | — | 1.1% | Dec 19, 2014 | GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in ... |
| CVE-2014-6396 | — | — | 3.6% | Dec 19, 2014 | The dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to caus... |
| CVE-2014-6395 | — | — | 13.1% | Dec 19, 2014 | Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 a... |
| CVE-2014-2716 | — | — | 1.4% | Dec 19, 2014 | Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activat... |
| CVE-2014-2026 | — | — | 1.9% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 On... |
| CVE-2014-8272 | — | — | 21.2% | Dec 19, 2014 | The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 ... |
| CVE-2014-7268 | — | — | 1.1% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in the data-export feature in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and ear... |
| CVE-2014-7267 | — | — | 0.9% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in the output-page generator in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and e... |
| CVE-2014-7249 | — | — | 6.1% | Dec 19, 2014 | Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648... |
| CVE-2014-7241 | — | — | 2.0% | Dec 19, 2014 | The TSUTAYA application 5.3 and earlier for Android allows remote attackers to execute arbitrary Java methods via a craf... |
| CVE-2014-8902 | — | — | 1.8% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t... |
| CVE-2014-8016 | — | — | 1.2% | Dec 19, 2014 | The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption)... |
| CVE-2014-6193 | — | — | 1.6% | Dec 19, 2014 | IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows... |
| CVE-2014-6173 | — | — | 0.8% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 8.... |
| CVE-2014-6171 | — | — | 1.8% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,... |
| CVE-2014-4801 | — | — | 0.8% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4,... |
| CVE-2014-8901 | — | — | 2.2% | Dec 18, 2014 | IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 allows remote authent... |
| CVE-2014-8890 | — | — | 2.3% | Dec 18, 2014 | IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leve... |
| CVE-2014-8014 | — | — | 1.2% | Dec 18, 2014 | Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now