2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-5288HIGH8.8A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
CVE-2014-7224HIGH8.8A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the acc...
CVE-2014-6413MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/p...
CVE-2014-9530CRITICAL9.8A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impac...
CVE-2014-2875MEDIUM6.1The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which al...
CVE-2014-10400MEDIUM6.1The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predi...
CVE-2014-10399MEDIUM6.1The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbit...
CVE-2014-8271MEDIUM6.8Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain...
CVE-2014-2030HIGH8.8Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remot...
CVE-2014-1958HIGH8.8Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attacke...
CVE-2014-3893Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0114. Reason: This candidate is a duplicate of C...
CVE-2014-8328MEDIUM5.3The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attacker...
CVE-2014-8141HIGH7.8Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to exe...
CVE-2014-2025CRITICAL9.8Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5...
CVE-2014-8338MEDIUM6.1Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhis...
CVE-2014-8322CRITICAL9.8Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac...
CVE-2014-8321HIGH7.8Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local use...
CVE-2014-8140HIGH7.8Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to ex...
CVE-2014-8139HIGH7.8Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execut...
CVE-2014-8126HIGH8.8The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.
CVE-2014-5236HIGH7.5Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 a...
CVE-2014-5039CRITICAL9.6Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attacke...
CVE-2014-3868HIGH8.8Multiple SQL injection vulnerabilities in ZeusCart 4.x.
CVE-2014-3809MEDIUM6.1Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS...
CVE-2014-3119HIGH8.8Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitr...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now