2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8501 | — | — | 5.2% | Dec 9, 2014 | The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to caus... |
| CVE-2014-8485 | — | — | 7.5% | Dec 9, 2014 | The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a deni... |
| CVE-2014-8484 | — | — | 5.1% | Dec 9, 2014 | The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of... |
| CVE-2014-9350 | — | — | 7.2% | Dec 8, 2014 | TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack... |
| CVE-2014-9349 | — | — | 3.2% | Dec 8, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to ... |
| CVE-2014-9348 | — | — | 2.3% | Dec 8, 2014 | SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote atta... |
| CVE-2014-9347 | — | — | 1.3% | Dec 8, 2014 | SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL comma... |
| CVE-2014-9346 | — | — | 0.9% | Dec 8, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal ... |
| CVE-2014-9345 | — | — | 2.3% | Dec 8, 2014 | SQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows r... |
| CVE-2014-9344 | — | — | 2.3% | Dec 8, 2014 | Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authe... |
| CVE-2014-9343 | — | — | 2.2% | Dec 8, 2014 | Open redirect vulnerability in modules/system/controller/selectlanguage.class.php in Snowfox CMS 1.0 allows remote attac... |
| CVE-2014-9305 | — | — | 3.7% | Dec 8, 2014 | SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be... |
| CVE-2014-9280 | — | — | 3.1% | Dec 8, 2014 | The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers ... |
| CVE-2014-9279 | — | — | 2.1% | Dec 8, 2014 | The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows re... |
| CVE-2014-9273 | — | — | 0.6% | Dec 8, 2014 | lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive fi... |
| CVE-2014-9270 | — | — | 2.1% | Dec 8, 2014 | Cross-site scripting (XSS) vulnerability in the projax_array_serialize_for_autocomplete function in core/projax_api.php ... |
| CVE-2014-9268 | — | — | 4.7% | Dec 8, 2014 | The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to ex... |
| CVE-2014-9267 | — | — | 3.4% | Dec 8, 2014 | Heap-based buffer overflow in the PTC IsoView ActiveX control allows remote attackers to execute arbitrary code via a cr... |
| CVE-2014-9266 | — | — | 2.6% | Dec 8, 2014 | The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attack... |
| CVE-2014-9265 | — | — | 4.0% | Dec 8, 2014 | Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remo... |
| CVE-2014-9263 | — | — | 3.8% | Dec 8, 2014 | Multiple buffer overflows in the PocketNetNVRMediaClientAxCtrl.NVRMediaViewer.1 control in 3S Pocketnet Tech VMS allow r... |
| CVE-2014-9130 | — | — | 13.2% | Dec 8, 2014 | scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependen... |
| CVE-2014-9029 | — | — | 18.4% | Dec 8, 2014 | Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in ... |
| CVE-2014-8106 | — | — | 0.6% | Dec 8, 2014 | Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest ... |
| CVE-2014-5462 | — | — | 2.0% | Dec 8, 2014 | Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execut... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now