2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-2015——Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x,...
CVE-2014-8582——FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote atta...
CVE-2014-6032——Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Con...
CVE-2014-3615——The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
CVE-2014-8244——Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; befo...
CVE-2014-8243——Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; befo...
CVE-2014-8578——Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 be...
CVE-2014-3475——Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013....
CVE-2014-3474——Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu i...
CVE-2014-3473——Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in Op...
CVE-2014-8577——Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we...
CVE-2014-8509——The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code ...
CVE-2014-8495——Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached applic...
CVE-2014-8399——The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a de...
CVE-2014-8334——The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute a...
CVE-2014-8333——The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of ser...
CVE-2014-8082——lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via u...
CVE-2014-8081——lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks...
CVE-2014-7987——Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script ...
CVE-2014-7986——install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the ins...
CVE-2014-7985——Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local...
CVE-2014-7177——XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary ...
CVE-2014-3708——OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denia...
CVE-2014-2336——Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and ...
CVE-2014-2335——Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allo...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now