2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8950 | — | — | 1.5% | Nov 16, 2014 | Unspecified vulnerability in Check Point Security Gateway R77 and R77.10, when the (1) URL Filtering or (2) Identity Awa... |
| CVE-2014-3916 | — | — | 1.4% | Nov 16, 2014 | The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial ... |
| CVE-2014-3248 | — | — | 0.5% | Nov 16, 2014 | Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Fa... |
| CVE-2014-0250 | — | — | 3.7% | Nov 16, 2014 | Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact v... |
| CVE-2014-0228 | — | — | 3.5% | Nov 16, 2014 | Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions ... |
| CVE-2014-8949 | — | — | 7.5% | Nov 16, 2014 | The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitr... |
| CVE-2014-8948 | — | — | 3.7% | Nov 16, 2014 | Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows re... |
| CVE-2014-3756 | — | — | 1.5% | Nov 16, 2014 | The client in Mumble 1.2.x before 1.2.6 allows remote attackers to force the loading of an external file and cause a den... |
| CVE-2014-3755 | — | — | 2.5% | Nov 16, 2014 | The QSvg module in Qt, as used in the Mumble client 1.2.x before 1.2.6, allows remote attackers to cause a denial of ser... |
| CVE-2014-0233 | — | — | 1.7% | Nov 16, 2014 | Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary comm... |
| CVE-2014-3209 | — | — | 0.4% | Nov 16, 2014 | The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow lo... |
| CVE-2014-2667 | — | — | 0.4% | Nov 16, 2014 | Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and... |
| CVE-2014-2268 | — | — | 31.2% | Nov 16, 2014 | views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all... |
| CVE-2014-2684 | — | — | 1.6% | Nov 16, 2014 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zen... |
| CVE-2014-2683 | — | — | 2.4% | Nov 16, 2014 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendSe... |
| CVE-2014-2682 | — | — | 2.2% | Nov 16, 2014 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendSe... |
| CVE-2014-2681 | — | — | 2.6% | Nov 16, 2014 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendSe... |
| CVE-2014-8566 | — | — | 2.7% | Nov 15, 2014 | The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of ser... |
| CVE-2014-8565 | — | — | — | Nov 15, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8518. Reason: This candidate is a duplicate of... |
| CVE-2014-5388 | — | — | 0.4% | Nov 15, 2014 | Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest... |
| CVE-2014-3502 | — | — | 5.0% | Nov 15, 2014 | Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL wi... |
| CVE-2014-3501 | — | — | 3.7% | Nov 15, 2014 | Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary server... |
| CVE-2014-3500 | — | — | 4.1% | Nov 15, 2014 | Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL. |
| CVE-2014-3158 | — | — | 3.5% | Nov 15, 2014 | Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers ... |
| CVE-2014-4975 | — | — | 3.9% | Nov 15, 2014 | Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now