2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8960 | — | — | 1.6% | Nov 30, 2014 | Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin ... |
| CVE-2014-8959 | — | — | 2.7% | Nov 30, 2014 | Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.... |
| CVE-2014-8958 | — | — | 2.4% | Nov 30, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.... |
| CVE-2014-9150 | — | — | 2.3% | Nov 30, 2014 | Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows att... |
| CVE-2014-9090 | — | — | 0.4% | Nov 30, 2014 | The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faul... |
| CVE-2014-8989 | — | — | 0.5% | Nov 30, 2014 | The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespa... |
| CVE-2014-8884 | — | — | 0.6% | Nov 30, 2014 | Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbd... |
| CVE-2014-7843 | — | — | 0.4% | Nov 30, 2014 | The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel before 3.17.4 on the ARM64 platform allows ... |
| CVE-2014-7842 | — | — | 0.4% | Nov 30, 2014 | Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of servic... |
| CVE-2014-7841 | — | — | 5.2% | Nov 30, 2014 | The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation in the Linux kernel before 3.17.4... |
| CVE-2014-3688 | — | — | 5.9% | Nov 30, 2014 | The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory c... |
| CVE-2014-9089 | — | — | 2.4% | Nov 28, 2014 | Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to exec... |
| CVE-2014-8994 | — | — | 0.3% | Nov 28, 2014 | The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a sym... |
| CVE-2014-8801 | — | — | 18.6% | Nov 28, 2014 | Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress... |
| CVE-2014-8799 | — | — | 68.5% | Nov 28, 2014 | Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2... |
| CVE-2014-8429 | — | — | 2.2% | Nov 28, 2014 | Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows... |
| CVE-2014-8425 | — | — | 3.1% | Nov 28, 2014 | The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the confi... |
| CVE-2014-8424 | — | — | 59.6% | Nov 28, 2014 | ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authenticatio... |
| CVE-2014-8423 | — | — | 62.5% | Nov 28, 2014 | Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar... |
| CVE-2014-7850 | — | — | 1.9% | Nov 28, 2014 | Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arb... |
| CVE-2014-7178 | — | — | 5.1% | Nov 28, 2014 | Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is... |
| CVE-2014-6075 | — | — | 1.2% | Nov 28, 2014 | IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnera... |
| CVE-2014-4883 | — | — | 0.6% | Nov 28, 2014 | resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values... |
| CVE-2014-4832 | — | — | 1.1% | Nov 28, 2014 | IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnera... |
| CVE-2014-4831 | — | — | 1.0% | Nov 28, 2014 | IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnera... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now