2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6258 | — | — | 1.5% | Dec 15, 2014 | An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consum... |
| CVE-2014-6257 | — | — | 1.4% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL ... |
| CVE-2014-6256 | — | — | 1.5% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directo... |
| CVE-2014-6255 | — | — | 2.1% | Dec 15, 2014 | Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect user... |
| CVE-2014-6254 | — | — | 1.2% | Dec 15, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arb... |
| CVE-2014-6253 | — | — | 0.7% | Dec 15, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hij... |
| CVE-2014-6053 | — | — | 7.6% | Dec 15, 2014 | The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not proper... |
| CVE-2014-6052 | — | — | 6.8% | Dec 15, 2014 | The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain ... |
| CVE-2014-3583 | — | — | 10.5% | Dec 15, 2014 | The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows rem... |
| CVE-2014-2973 | — | — | — | Dec 15, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5753. Reason: This candidate is a duplicate of... |
| CVE-2014-1569 | — | — | 3.2% | Dec 15, 2014 | The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 a... |
| CVE-2014-8269 | — | — | 4.7% | Dec 13, 2014 | Multiple stack-based buffer overflows in (1) HWOPOSScale.ocx and (2) HWOPOSSCANNER.ocx in Honeywell OPOS Suite before 1.... |
| CVE-2014-3364 | — | — | 0.9% | Dec 13, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.... |
| CVE-2014-4633 | — | — | 0.9% | Dec 12, 2014 | Cross-site scripting (XSS) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5.1.1 allows remote attackers to in... |
| CVE-2014-4628 | — | — | 0.9% | Dec 12, 2014 | Cross-site scripting (XSS) vulnerability in EMC Isilon InsightIQ 2.x and 3.x before 3.1 allows remote attackers to injec... |
| CVE-2014-2516 | — | — | 1.6% | Dec 12, 2014 | Open redirect vulnerability in EMC RSA Authentication Manager 8.x before 8.1 Patch 6 allows remote attackers to redirect... |
| CVE-2014-6210 | — | — | 2.5% | Dec 12, 2014 | IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remo... |
| CVE-2014-6209 | — | — | 2.5% | Dec 12, 2014 | IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and W... |
| CVE-2014-9374 | — | — | 9.5% | Dec 12, 2014 | Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.... |
| CVE-2014-8956 | — | — | 0.6% | Dec 12, 2014 | Stack-based buffer overflow in the K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as... |
| CVE-2014-8608 | — | — | 0.5% | Dec 12, 2014 | The K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as used in multiple K7 Computing ... |
| CVE-2014-8515 | — | — | 2.4% | Dec 12, 2014 | The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pai... |
| CVE-2014-8489 | — | — | 2.9% | Dec 12, 2014 | Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote atta... |
| CVE-2014-8124 | — | — | 2.8% | Dec 12, 2014 | OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when... |
| CVE-2014-7840 | — | — | 4.1% | Dec 12, 2014 | The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now