2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-2843MEDIUM6.1Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows ...
CVE-2014-4860MEDIUM6.8Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI impl...
CVE-2014-4859MEDIUM6.8Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation...
CVE-2014-3719CRITICAL9.8Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management sys...
CVE-2014-3718MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library mana...
CVE-2014-8490MEDIUM6.1Cross-site scripting (XSS) vulnerability in TennisConnect COMPONENTS 9.927 allows remote attackers to inject arbitrary w...
CVE-2014-3856HIGH7The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows ...
CVE-2014-3230MEDIUM5.9The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket cla...
CVE-2014-2914CRITICAL9.8fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which ...
CVE-2014-2906HIGH7The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows lo...
CVE-2014-2898CRITICAL9.8wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read fun...
CVE-2014-2897CRITICAL9.8The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fa...
CVE-2014-2896CRITICAL9.8The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers ...
CVE-2014-3445CRITICAL9.8backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows ...
CVE-2014-2581HIGH7.5Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Addition...
CVE-2014-8563CRITICAL9.8Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
CVE-2014-5500MEDIUM6.1Synacor Zimbra Collaboration before 8.0.8 has XSS.
CVE-2014-8742HIGH7.5Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allow...
CVE-2014-8741CRITICAL9.8Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo...
CVE-2014-7303HIGH7.8SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain pas...
CVE-2014-7302HIGH7.8SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the...
CVE-2014-7301MEDIUM6.6SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain pas...
CVE-2014-3979HIGH7.5Bytemark Symbiosis allows remote attackers to cause a denial of service via a crafted username, which triggers the firew...
CVE-2014-9481MEDIUM5.9The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive ...
CVE-2014-8161MEDIUM4.3PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows re...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now