2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2015 | — | — | 3.9% | Nov 2, 2014 | Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x,... |
| CVE-2014-8582 | — | — | 1.3% | Nov 1, 2014 | FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote atta... |
| CVE-2014-6032 | — | — | 2.9% | Nov 1, 2014 | Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Con... |
| CVE-2014-3615 | — | — | 0.4% | Nov 1, 2014 | The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. |
| CVE-2014-8244 | — | — | 4.0% | Nov 1, 2014 | Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; befo... |
| CVE-2014-8243 | — | — | 1.2% | Nov 1, 2014 | Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; befo... |
| CVE-2014-8578 | — | — | 1.2% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 be... |
| CVE-2014-3475 | — | — | 1.2% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.... |
| CVE-2014-3474 | — | — | 1.9% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu i... |
| CVE-2014-3473 | — | — | 1.7% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in Op... |
| CVE-2014-8577 | — | — | 4.3% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we... |
| CVE-2014-8509 | — | — | 5.1% | Oct 31, 2014 | The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code ... |
| CVE-2014-8495 | — | — | 1.6% | Oct 31, 2014 | Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached applic... |
| CVE-2014-8399 | — | — | 0.4% | Oct 31, 2014 | The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a de... |
| CVE-2014-8334 | — | — | 3.5% | Oct 31, 2014 | The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute a... |
| CVE-2014-8333 | — | — | 2.0% | Oct 31, 2014 | The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of ser... |
| CVE-2014-8082 | — | — | 2.6% | Oct 31, 2014 | lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via u... |
| CVE-2014-8081 | — | — | 4.2% | Oct 31, 2014 | lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks... |
| CVE-2014-7987 | — | — | 2.2% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script ... |
| CVE-2014-7986 | — | — | 2.9% | Oct 31, 2014 | install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the ins... |
| CVE-2014-7985 | — | — | 5.0% | Oct 31, 2014 | Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local... |
| CVE-2014-7177 | — | — | 3.3% | Oct 31, 2014 | XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary ... |
| CVE-2014-3708 | — | — | 2.8% | Oct 31, 2014 | OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denia... |
| CVE-2014-2336 | — | — | 1.8% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and ... |
| CVE-2014-2335 | — | — | 1.1% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now