2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-1929python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "op...
CVE-2014-1928The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attac...
CVE-2014-1927The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers...
CVE-2014-3636D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prev...
CVE-2014-6611The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and b...
CVE-2014-6152Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Integrated Portal (TIP) 2.2.x allow remote authenticat...
CVE-2014-6151CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arb...
CVE-2014-4624EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authenticatio...
CVE-2014-4623EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Ha...
CVE-2014-4620The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, st...
CVE-2014-3409The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13...
CVE-2014-8760ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to ...
CVE-2014-7180Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and...
CVE-2014-6251Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a ...
CVE-2014-6230WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the ...
CVE-2014-3604Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domai...
CVE-2014-2021Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 a...
CVE-2014-8346The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a net...
CVE-2014-7298adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX ...
CVE-2014-8073Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the ...
CVE-2014-8072The administration module in OpenMRS 2.1 Standalone Edition allows remote authenticated users to obtain read access via ...
CVE-2014-8071Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject a...
CVE-2014-7292Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.1612...
CVE-2014-7281Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a...
CVE-2014-2230Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now