Skip to main content

Year archive

CVEs published in 2014

Archive summary

7,928 CVEs published in 2014 — 793 Critical, 1,160 High, 5,317 Medium, 658 Low, 0 Unrated.

CVE-2013-6642

Published Jan 16, 2014

Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1473

Published Jan 16, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to hijack the a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1472

Published Jan 16, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to inject arbitrary we…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7294

Published Jan 16, 2014

The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification with…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0496

Published Jan 15, 2014

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecif…

CVSS 8.8 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2014-0262

Published Jan 15, 2014

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, wh…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0261

Published Jan 15, 2014

Microsoft Dynamics AX 4.0 SP2, 2009 SP1, 2012, and 2012 R2 allows remote authenticated users to cause a denial of service (instance outage) via crafted data to an Application Obje…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7293

Published Jan 15, 2014

The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to instead access a DNS hostname tha…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0665

Published Jan 15, 2014

The RBAC implementation in Cisco Identity Services Engine (ISE) Software does not properly verify privileges for support-bundle downloads, which allows remote authenticated users…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6142

Published Jan 15, 2014

DNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCADA Expert ClearSCADA 2013 R1 through 2013 R1.2 allows remote attackers to cause…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5890

Published Jan 15, 2014

Unspecified vulnerability in the Oracle Payroll component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, 12.1.3, and 12.2.2 allows remote authenticated users to aff…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5889

Published Jan 15, 2014

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 7,626-7,650 of 7,928 CVEsPage 306 of 318