2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7228 | — | — | 55.1% | Nov 3, 2014 | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb... |
| CVE-2014-0490 | — | — | 3.6% | Nov 3, 2014 | The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote... |
| CVE-2014-0489 | — | — | 3.6% | Nov 3, 2014 | APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote atta... |
| CVE-2014-0488 | — | — | 2.1% | Nov 3, 2014 | APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which... |
| CVE-2014-0487 | — | — | 1.9% | Nov 3, 2014 | APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since he... |
| CVE-2014-8494 | — | — | 0.5% | Nov 3, 2014 | ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe,... |
| CVE-2014-8350 | — | — | 3.1% | Nov 3, 2014 | Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as de... |
| CVE-2014-8080 | — | — | 5.5% | Nov 3, 2014 | The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attacker... |
| CVE-2014-5507 | — | — | 0.9% | Nov 3, 2014 | iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user... |
| CVE-2014-5272 | — | — | 2.6% | Nov 3, 2014 | libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote a... |
| CVE-2014-5271 | — | — | 4.8% | Nov 3, 2014 | Heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFMpeg before 1.1.14, 1.2.x ... |
| CVE-2014-3712 | — | — | 1.7% | Nov 3, 2014 | Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setu... |
| CVE-2014-3654 | — | — | 1.8% | Nov 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satel... |
| CVE-2014-3683 | — | — | 4.6% | Nov 2, 2014 | Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to ca... |
| CVE-2014-3634 | — | — | 7.5% | Nov 2, 2014 | rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of serv... |
| CVE-2014-2015 | — | — | 3.9% | Nov 2, 2014 | Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x,... |
| CVE-2014-8582 | — | — | 1.3% | Nov 1, 2014 | FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote atta... |
| CVE-2014-6032 | — | — | 2.9% | Nov 1, 2014 | Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Con... |
| CVE-2014-3615 | — | — | 0.4% | Nov 1, 2014 | The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. |
| CVE-2014-8244 | — | — | 4.0% | Nov 1, 2014 | Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; befo... |
| CVE-2014-8243 | — | — | 1.2% | Nov 1, 2014 | Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; befo... |
| CVE-2014-8578 | — | — | 1.2% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 be... |
| CVE-2014-3475 | — | — | 1.2% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.... |
| CVE-2014-3474 | — | — | 1.9% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu i... |
| CVE-2014-3473 | — | — | 1.7% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in Op... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now