2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9030 | — | — | 2.2% | Nov 24, 2014 | The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which a... |
| CVE-2014-9016 | — | — | 82.7% | Nov 24, 2014 | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x... |
| CVE-2014-9015 | — | — | 2.5% | Nov 24, 2014 | Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstr... |
| CVE-2014-8991 | — | — | 0.4% | Nov 24, 2014 | pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a... |
| CVE-2014-8988 | — | — | 2.0% | Nov 24, 2014 | MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_att... |
| CVE-2014-8986 | — | — | 1.2% | Nov 24, 2014 | Cross-site scripting (XSS) vulnerability in the selection list in the filters in the Configuration Report page (adm_conf... |
| CVE-2014-8627 | — | — | 2.1% | Nov 24, 2014 | PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct down... |
| CVE-2014-8418 | — | — | 3.6% | Nov 24, 2014 | The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x... |
| CVE-2014-8417 | — | — | 2.4% | Nov 24, 2014 | ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 befor... |
| CVE-2014-8416 | — | — | 4.3% | Nov 24, 2014 | Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0... |
| CVE-2014-8415 | — | — | 3.0% | Nov 24, 2014 | Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows... |
| CVE-2014-8414 | — | — | 2.3% | Nov 24, 2014 | ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state ... |
| CVE-2014-8413 | — | — | 2.1% | Nov 24, 2014 | The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and ... |
| CVE-2014-8412 | — | — | 2.7% | Nov 24, 2014 | The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1... |
| CVE-2014-7821 | — | — | 3.9% | Nov 24, 2014 | OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of se... |
| CVE-2014-7817 | — | — | 0.6% | Nov 24, 2014 | The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-depend... |
| CVE-2014-1424 | — | — | 1.6% | Nov 24, 2014 | apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmo... |
| CVE-2014-9060 | — | — | 2.1% | Nov 24, 2014 | The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properl... |
| CVE-2014-9059 | — | — | 1.8% | Nov 24, 2014 | lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide ... |
| CVE-2014-7848 | — | — | 2.1% | Nov 24, 2014 | lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitiv... |
| CVE-2014-7847 | — | — | 2.4% | Nov 24, 2014 | iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remot... |
| CVE-2014-7846 | — | — | 1.7% | Nov 24, 2014 | tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does n... |
| CVE-2014-7845 | — | — | 2.4% | Nov 24, 2014 | The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 ... |
| CVE-2014-7838 | — | — | 1.0% | Nov 24, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.... |
| CVE-2014-7837 | — | — | 1.9% | Nov 24, 2014 | mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remot... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now