2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8559 | MEDIUM | 5.5 | 0.7% | Nov 10, 2014 | The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename... |
| CVE-2014-3690 | MEDIUM | 5.5 | 0.5% | Nov 10, 2014 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the v... |
| CVE-2014-3647 | MEDIUM | 5.5 | 0.6% | Nov 10, 2014 | arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, wh... |
| CVE-2014-3646 | MEDIUM | 5.5 | 0.4% | Nov 10, 2014 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID... |
| CVE-2014-3611 | MEDIUM | 4.7 | 0.3% | Nov 10, 2014 | Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel ... |
| CVE-2014-3610 | MEDIUM | 5.5 | 0.6% | Nov 10, 2014 | The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the ... |
| CVE-2014-8086 | MEDIUM | 4.7 | 0.4% | Oct 13, 2014 | Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local user... |
| CVE-2014-7975 | MEDIUM | 5.5 | 0.5% | Oct 13, 2014 | The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability ... |
| CVE-2014-7970 | MEDIUM | 5.5 | 0.7% | Oct 13, 2014 | The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain... |
| CVE-2014-4806 | MEDIUM | 5.5 | 0.3% | Aug 29, 2014 | The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, ... |
| CVE-2014-5455 | MEDIUM | 5.3 | 1.0% | Aug 25, 2014 | Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and Ope... |
| CVE-2014-3480 | MEDIUM | 6.5 | 11.5% | Jul 9, 2014 | The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.... |
| CVE-2014-3478 | MEDIUM | 6.5 | 15.2% | Jul 9, 2014 | Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP be... |
| CVE-2014-0207 | MEDIUM | 6.5 | 16.9% | Jul 9, 2014 | The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 ... |
| CVE-2014-3477 | MEDIUM | 4 | 0.4% | Jul 1, 2014 | The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error t... |
| CVE-2014-2005 | MEDIUM | 6.8 | 0.5% | Jun 25, 2014 | Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentic... |
| CVE-2014-0203 | MEDIUM | 5.5 | 0.5% | Jun 23, 2014 | The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname... |
| CVE-2014-3146 | MEDIUM | 6.1 | 6.3% | May 14, 2014 | Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct... |
| CVE-2014-0196 | MEDIUM | 5.5 | 22.5% | May 7, 2014 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a... |
| CVE-2014-1530 | MEDIUM | 6.1 | 1.7% | Apr 30, 2014 | The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and S... |
| CVE-2014-1523 | MEDIUM | 6.5 | 3.2% | Apr 30, 2014 | Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunde... |
| CVE-2014-2653 | MEDIUM | 6.5 | 2.0% | Mar 27, 2014 | The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger t... |
| CVE-2014-2526 | MEDIUM | 6.1 | 1.7% | Mar 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7 allow remote attackers to inject arbitr... |
| CVE-2014-1496 | MEDIUM | 5.5 | 0.4% | Mar 19, 2014 | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allo... |
| CVE-2014-2120 | MEDIUM | 6.1 | 14.0% | Mar 19, 2014 | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software al... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now