Skip to main content

Year archive

CVEs published in 2014

Archive summary

7,928 CVEs published in 2014 — 793 Critical, 1,160 High, 5,317 Medium, 658 Low, 0 Unrated.

CVE-2013-7078

Published Jan 19, 2014

Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16,…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4375

Published Jan 19, 2014

The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant refe…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2142

Published Jan 19, 2014

userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem,…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1438

Published Jan 19, 2014

Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0244

Published Jan 19, 2014

Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows rem…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4231

Published Jan 19, 2014

Multiple buffer overflows in libtiff before 4.0.3 allow remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) extension block in a GIF image or (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3483

Published Jan 19, 2014

Stack-based buffer overflow in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (appl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3482

Published Jan 19, 2014

Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1446

Published Jan 18, 2014

The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1445

Published Jan 18, 2014

The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sen…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1444

Published Jan 18, 2014

The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1438

Published Jan 18, 2014

The restore_fpu_checking function in arch/x86/include/asm/fpu-internal.h in the Linux kernel before 3.12.8 on the AMD K7 and K8 platforms does not clear pending exceptions before…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1740

Published Jan 18, 2014

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-mi…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6425

Published Jan 18, 2014

Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial…

CVSS 5.0 · Medium

CVE-2014-1211

Published Jan 17, 2014

Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1207

Published Jan 17, 2014

VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7295

Published Jan 17, 2014

Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0792

Published Jan 17, 2014

Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintend…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 7,576-7,600 of 7,928 CVEsPage 304 of 318