Skip to main content

Daily materialized evidence profile

Year 2014

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
7,928
CVEs with mentions
419
Total mentions
997
CVEs with KEV
34
CVEs with PoC
2

Attack vector counts

Network
5,678
Adjacent network
1,543
Local
705
Physical
2

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2014-6271

Published Sep 24, 2014

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cr…

CVSS 9.8 · Critical
evidence mentions
36
Buzz score
83.6
KEV listedPublic PoC observed

CVE-2014-0160

Published Apr 7, 2014

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive infor…

CVSS 7.5 · High
evidence mentions
46
Buzz score
72.5
KEV listed

CVE-2014-6332

Published Nov 11, 2014

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold an…

CVSS 8.8 · High
evidence mentions
42
Buzz score
71.0
KEV listed

CVE-2014-0322

Published Feb 14, 2014

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and…

CVSS 8.8 · High
evidence mentions
28
Buzz score
71.0
KEV listed

CVE-2014-4114

Published Oct 15, 2014

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote a…

CVSS 7.8 · High
evidence mentions
27
Buzz score
71.0
KEV listed