2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5466 | — | — | 0.9% | Dec 16, 2014 | Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x b... |
| CVE-2014-5359 | — | — | 3.8% | Dec 16, 2014 | Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard)... |
| CVE-2014-4936 | — | — | 16.8% | Dec 16, 2014 | The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)... |
| CVE-2014-9386 | — | — | 2.0% | Dec 15, 2014 | Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote att... |
| CVE-2014-9385 | — | — | 1.2% | Dec 15, 2014 | Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the au... |
| CVE-2014-9252 | — | — | 0.4% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain... |
| CVE-2014-9251 | — | — | 1.3% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attack... |
| CVE-2014-9250 | — | — | 1.5% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, wh... |
| CVE-2014-9249 | — | — | 1.6% | Dec 15, 2014 | The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by conn... |
| CVE-2014-9248 | — | — | 1.2% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain ac... |
| CVE-2014-9247 | — | — | 1.1% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address,... |
| CVE-2014-9246 | — | — | — | Dec 15, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9385, CVE-2014-9386. Reason: this ID was inten... |
| CVE-2014-9245 | — | — | 1.4% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename acti... |
| CVE-2014-8967 | — | — | 12.4% | Dec 15, 2014 | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a craf... |
| CVE-2014-8610 | — | — | 0.3% | Dec 15, 2014 | AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which... |
| CVE-2014-8609 | — | — | 0.6% | Dec 15, 2014 | The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Androi... |
| CVE-2014-8507 | — | — | 1.6% | Dec 15, 2014 | Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap... |
| CVE-2014-7911 | — | — | 24.3% | Dec 15, 2014 | luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.... |
| CVE-2014-6261 | — | — | 19.7% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to... |
| CVE-2014-6260 | — | — | 1.8% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote att... |
| CVE-2014-6259 | — | — | 1.6% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers t... |
| CVE-2014-6258 | — | — | 1.5% | Dec 15, 2014 | An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consum... |
| CVE-2014-6257 | — | — | 1.4% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL ... |
| CVE-2014-6256 | — | — | 1.5% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directo... |
| CVE-2014-6255 | — | — | 2.1% | Dec 15, 2014 | Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect user... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now