2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4156 | MEDIUM | 5.3 | 1.2% | Jan 27, 2020 | Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability |
| CVE-2014-9630 | HIGH | 7.8 | 1.5% | Jan 24, 2020 | The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a s... |
| CVE-2014-9629 | HIGH | 7.8 | 2.4% | Jan 24, 2020 | Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.... |
| CVE-2014-9628 | HIGH | 7.8 | 2.2% | Jan 24, 2020 | The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote at... |
| CVE-2014-9627 | HIGH | 7.8 | 1.1% | Jan 24, 2020 | The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an inco... |
| CVE-2014-9626 | HIGH | 7.8 | 1.5% | Jan 24, 2020 | Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2... |
| CVE-2014-9625 | HIGH | 7.8 | 2.4% | Jan 24, 2020 | The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorre... |
| CVE-2014-4172 | CRITICAL | 9.8 | 6.1% | Jan 24, 2020 | A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasi... |
| CVE-2014-9720 | MEDIUM | 6.5 | 2.5% | Jan 24, 2020 | Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, wh... |
| CVE-2014-1925 | CRITICAL | 9.8 | 2.0% | Jan 24, 2020 | SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha befo... |
| CVE-2014-1924 | CRITICAL | 9.8 | 2.0% | Jan 24, 2020 | The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.1... |
| CVE-2014-1923 | HIGH | 7.5 | 3.5% | Jan 24, 2020 | Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picuploa... |
| CVE-2014-1922 | HIGH | 7.5 | 2.3% | Jan 24, 2020 | Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before ... |
| CVE-2014-2050 | MEDIUM | 6.5 | 1.5% | Jan 23, 2020 | Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote at... |
| CVE-2014-3606 | — | — | — | Jan 23, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2014-7238 | MEDIUM | 6.1 | 1.1% | Jan 23, 2020 | The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS |
| CVE-2014-2680 | HIGH | 8.1 | 1.9% | Jan 21, 2020 | The update process in Xmind 3.4.1 and earlier allow remote attackers to execute arbitrary code via a man-in-the-middle a... |
| CVE-2014-5007 | CRITICAL | 9.8 | 37.3% | Jan 17, 2020 | Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop ... |
| CVE-2014-6448 | HIGH | 7.8 | 0.3% | Jan 15, 2020 | Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restr... |
| CVE-2014-7844 | HIGH | 7.8 | 1.6% | Jan 14, 2020 | BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address. |
| CVE-2014-2271 | HIGH | 8.1 | 1.5% | Jan 14, 2020 | cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R0... |
| CVE-2014-5238 | HIGH | 7.8 | 1.9% | Jan 14, 2020 | XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 all... |
| CVE-2014-5138 | HIGH | 7.5 | 1.6% | Jan 14, 2020 | Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instan... |
| CVE-2014-4610 | HIGH | 8.8 | 4.5% | Jan 14, 2020 | Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before ... |
| CVE-2014-4609 | HIGH | 8.8 | 5.7% | Jan 14, 2020 | Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now