2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4156MEDIUM5.3Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability
CVE-2014-9630HIGH7.8The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a s...
CVE-2014-9629HIGH7.8Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2....
CVE-2014-9628HIGH7.8The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote at...
CVE-2014-9627HIGH7.8The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an inco...
CVE-2014-9626HIGH7.8Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2...
CVE-2014-9625HIGH7.8The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorre...
CVE-2014-4172CRITICAL9.8A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasi...
CVE-2014-9720MEDIUM6.5Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, wh...
CVE-2014-1925CRITICAL9.8SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha befo...
CVE-2014-1924CRITICAL9.8The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.1...
CVE-2014-1923HIGH7.5Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picuploa...
CVE-2014-1922HIGH7.5Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before ...
CVE-2014-2050MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote at...
CVE-2014-3606Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2014-7238MEDIUM6.1The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
CVE-2014-2680HIGH8.1The update process in Xmind 3.4.1 and earlier allow remote attackers to execute arbitrary code via a man-in-the-middle a...
CVE-2014-5007CRITICAL9.8Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop ...
CVE-2014-6448HIGH7.8Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restr...
CVE-2014-7844HIGH7.8BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
CVE-2014-2271HIGH8.1cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R0...
CVE-2014-5238HIGH7.8XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 all...
CVE-2014-5138HIGH7.5Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instan...
CVE-2014-4610HIGH8.8Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before ...
CVE-2014-4609HIGH8.8Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10....

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now