2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9601 | — | — | 5.4% | Jan 16, 2015 | Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that... |
| CVE-2014-9496 | — | — | 0.6% | Jan 16, 2015 | The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related ... |
| CVE-2014-9480 | — | — | 1.2% | Jan 16, 2015 | Cross-site scripting (XSS) vulnerability in the Hovercards extension for MediaWiki allows remote attackers to inject arb... |
| CVE-2014-9479 | — | — | 1.2% | Jan 16, 2015 | Cross-site scripting (XSS) vulnerability in the preview in the TemplateSandbox extension for MediaWiki allows remote att... |
| CVE-2014-9478 | — | — | 1.2% | Jan 16, 2015 | Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML ... |
| CVE-2014-9477 | — | — | 1.2% | Jan 16, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki allow remote attackers to in... |
| CVE-2014-9476 | — | — | 2.2% | Jan 16, 2015 | MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS res... |
| CVE-2014-9475 | — | — | 1.4% | Jan 16, 2015 | Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.... |
| CVE-2014-9471 | — | — | 7.1% | Jan 16, 2015 | The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly ex... |
| CVE-2014-7814 | — | — | 1.4% | Jan 16, 2015 | SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to ... |
| CVE-2014-6386 | — | — | 2.7% | Jan 16, 2015 | Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12... |
| CVE-2014-6385 | — | — | 0.6% | Jan 16, 2015 | Juniper Junos 11.4 before 11.4R13, 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, 1... |
| CVE-2014-6384 | — | — | 0.3% | Jan 16, 2015 | Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13... |
| CVE-2014-6383 | — | — | 2.1% | Jan 16, 2015 | The stateless firewall in Juniper Junos 13.3R3, 14.1R1, and 14.1R2, when using Trio-based PFE modules, does not properly... |
| CVE-2014-6382 | — | — | 1.2% | Jan 16, 2015 | The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50... |
| CVE-2014-3692 | — | — | 2.9% | Jan 16, 2015 | The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root a... |
| CVE-2014-1949 | — | — | 0.3% | Jan 16, 2015 | GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically p... |
| CVE-2014-9600 | — | — | 0.7% | Jan 16, 2015 | Untrusted search path vulnerability in Macroplant iExplorer 3.6.3.0 allows local users to execute arbitrary code and con... |
| CVE-2014-9599 | — | — | 2.2% | Jan 16, 2015 | Cross-site scripting (XSS) vulnerability in the filemanager in b2evolution before 5.2.1 allows remote attackers to injec... |
| CVE-2014-9596 | — | — | 0.7% | Jan 15, 2015 | Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU before 9.3.1 build 4.08.003.0, when USB Wi-Fi or Direct LAN is ena... |
| CVE-2014-8904 | — | — | 1.0% | Jan 15, 2015 | lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCM... |
| CVE-2014-8034 | — | — | 1.4% | Jan 15, 2015 | Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for re... |
| CVE-2014-8022 | — | — | 1.8% | Jan 15, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity Services Engine allow remote attackers to inject a... |
| CVE-2014-7881 | — | — | 1.6% | Jan 15, 2015 | Cross-site scripting (XSS) vulnerability in the server in HP Insight Control allows remote attackers to inject arbitrary... |
| CVE-2014-9595 | — | — | 2.4% | Jan 15, 2015 | Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated us... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now