2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7136 | — | — | 0.6% | Dec 12, 2014 | Heap-based buffer overflow in the K7FWFilt.sys kernel mode driver (aka K7Firewall Packet Driver) before 14.0.1.16, as us... |
| CVE-2014-6408 | — | — | 3.1% | Dec 12, 2014 | Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly by... |
| CVE-2014-6407 | — | — | 4.9% | Dec 12, 2014 | Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or ... |
| CVE-2014-6381 | — | — | 0.5% | Dec 12, 2014 | Juniper WLC devices with WLAN Software releases 8.0.x before 8.0.4, 9.0.x before 9.0.2.11, 9.0.3.x before 9.0.3.5, and 9... |
| CVE-2014-9365 | — | — | 3.3% | Dec 12, 2014 | The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x be... |
| CVE-2014-8270 | — | — | 20.1% | Dec 12, 2014 | BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose na... |
| CVE-2014-7265 | — | — | 0.9% | Dec 12, 2014 | Cross-site scripting (XSS) vulnerability in LinPHA allows remote attackers to inject arbitrary web script or HTML via un... |
| CVE-2014-6316 | — | — | 2.3% | Dec 12, 2014 | core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which a... |
| CVE-2014-6145 | — | — | 1.1% | Dec 12, 2014 | Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 befo... |
| CVE-2014-6138 | — | — | 1.1% | Dec 12, 2014 | The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended g... |
| CVE-2014-4323 | — | — | 3.6% | Dec 12, 2014 | The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in... |
| CVE-2014-7250 | — | — | 4.7% | Dec 12, 2014 | The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly ... |
| CVE-2014-4815 | — | — | 0.9% | Dec 12, 2014 | Session fixation vulnerability in IBM Rational Lifecycle Integration Adapter for Windchill 1.x before 1.0.1 allows remot... |
| CVE-2014-7263 | — | — | 1.5% | Dec 12, 2014 | Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script o... |
| CVE-2014-7262 | — | — | 1.8% | Dec 12, 2014 | Cross-site scripting (XSS) vulnerability in the Omake BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to in... |
| CVE-2014-7261 | — | — | 1.1% | Dec 12, 2014 | Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script o... |
| CVE-2014-7260 | — | — | 2.1% | Dec 12, 2014 | The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote atta... |
| CVE-2014-7264 | — | — | 1.4% | Dec 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users Managem... |
| CVE-2014-6215 | — | — | 1.4% | Dec 11, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,... |
| CVE-2014-6163 | — | — | 0.9% | Dec 11, 2014 | Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows rem... |
| CVE-2014-6143 | — | — | 0.3% | Dec 11, 2014 | The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by ... |
| CVE-2014-3058 | — | — | 0.5% | Dec 11, 2014 | Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 all... |
| CVE-2014-9264 | — | — | 3.9% | Dec 11, 2014 | Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary c... |
| CVE-2014-9192 | — | — | 2.7% | Dec 11, 2014 | Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and... |
| CVE-2014-8373 | — | — | 3.6% | Dec 11, 2014 | The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote au... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now