2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-10000 | — | — | — | Jan 13, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This ID is frequently used as an example o... |
| CVE-2014-6268 | — | — | 0.4% | Jan 12, 2015 | The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via... |
| CVE-2014-2839 | — | — | 1.6% | Jan 12, 2015 | SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arb... |
| CVE-2014-2838 | — | — | 1.0% | Jan 12, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote... |
| CVE-2014-9495 | HIGH | 8.8 | 3.9% | Jan 10, 2015 | Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running... |
| CVE-2014-9191 | — | — | 0.4% | Jan 10, 2015 | The CodeWrights HART Device Type Manager (DTM) library in Emerson HART DTM before 1.4.181 allows physically proximate at... |
| CVE-2014-9190 | — | — | 6.1% | Jan 10, 2015 | Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote ... |
| CVE-2014-8036 | — | — | 1.3% | Jan 10, 2015 | The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attacke... |
| CVE-2014-8035 | — | — | 1.4% | Jan 10, 2015 | The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whet... |
| CVE-2014-8020 | — | — | 2.4% | Jan 10, 2015 | Cisco Unified Communication Domain Manager Platform Software allows remote attackers to cause a denial of service (CPU c... |
| CVE-2014-6212 | — | — | 1.4% | Jan 10, 2015 | The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x ... |
| CVE-2014-6199 | — | — | 2.0% | Jan 10, 2015 | The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote... |
| CVE-2014-6158 | — | — | 3.7% | Jan 10, 2015 | Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4... |
| CVE-2014-3096 | — | — | 0.8% | Jan 10, 2015 | Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authentica... |
| CVE-2014-1155 | — | — | — | Jan 10, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9580. Reason: This candidate is not authorized... |
| CVE-2014-1137 | — | — | — | Jan 10, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9445, CVE-2014-9581, CVE-2014-9582. Reason: Th... |
| CVE-2014-1004 | — | — | — | Jan 10, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9456. Reason: This candidate is not authorized... |
| CVE-2014-9585 | — | — | 0.6% | Jan 9, 2015 | The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locatio... |
| CVE-2014-9584 | — | — | 0.5% | Jan 9, 2015 | The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a le... |
| CVE-2014-9529 | — | — | 0.3% | Jan 9, 2015 | Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local ... |
| CVE-2014-9510 | — | — | 1.0% | Jan 9, 2015 | Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firm... |
| CVE-2014-9505 | — | — | 1.0% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in the School Administration module 7.x-1.x before 7.x-1.8 for Drupal allows re... |
| CVE-2014-9501 | — | — | 0.9% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in the Poll Chart Block module 7.x-1.x before 7.x-1.2 for Drupal allows remote ... |
| CVE-2014-9500 | — | — | 1.2% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in the Moip module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to... |
| CVE-2014-9499 | — | — | 0.9% | Jan 9, 2015 | Cross-site scripting (XSS) vulnerability in the Godwin's Law module before 7.x-1.1 for Drupal, when using the dblog modu... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now