2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4975Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain ...
CVE-2014-3707The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, ...
CVE-2014-7998Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to caus...
CVE-2014-7997The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short lease...
CVE-2014-7248Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows remote attackers to inject arbitrary web script o...
CVE-2014-8567The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) ...
CVE-2014-7815The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a sma...
CVE-2014-3689The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and g...
CVE-2014-7991The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly va...
CVE-2014-7878The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived f...
CVE-2014-7246The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when dep...
CVE-2014-5424Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of ser...
CVE-2014-8770Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a an...
CVE-2014-8564The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x be...
CVE-2014-8557Multiple cross-site scripting (XSS) vulnerabilities in JExperts Channel Platform 5.0.33_CCB allow remote attackers to in...
CVE-2014-8554SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before...
CVE-2014-8476The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which...
CVE-2014-8359Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute...
CVE-2014-7823The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using t...
CVE-2014-3674Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to acc...
CVE-2014-3602Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote s...
CVE-2014-8736The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read fi...
CVE-2014-8735The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before 7.x-2.2216 for Drupal logs usernames and passwords,...
CVE-2014-8734The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "acces...
CVE-2014-8555Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attack...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now