2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6149 | — | — | 1.9% | Oct 29, 2014 | Directory traversal vulnerability in BIRT-viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 ... |
| CVE-2014-4877 | — | — | 39.9% | Oct 29, 2014 | Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to w... |
| CVE-2014-4839 | — | — | 0.5% | Oct 29, 2014 | Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 befo... |
| CVE-2014-3698 | — | — | 3.8% | Oct 29, 2014 | The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows r... |
| CVE-2014-3697 | — | — | 3.8% | Oct 29, 2014 | Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows a... |
| CVE-2014-3696 | — | — | 2.9% | Oct 29, 2014 | nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a... |
| CVE-2014-3695 | — | — | 2.9% | Oct 29, 2014 | markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of se... |
| CVE-2014-3694 | — | — | 2.3% | Oct 29, 2014 | The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 d... |
| CVE-2014-3670 | — | — | 22.6% | Oct 29, 2014 | The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x be... |
| CVE-2014-3669 | — | — | 28.9% | Oct 29, 2014 | Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5... |
| CVE-2014-3668 | — | — | 27.0% | Oct 29, 2014 | Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC ext... |
| CVE-2014-3051 | — | — | 0.6% | Oct 29, 2014 | The Internet Service Monitor (ISM) agent in IBM Tivoli Composite Application Manager (ITCAM) for Transactions 7.1 and 7.... |
| CVE-2014-6126 | — | — | 1.8% | Oct 28, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to inject arb... |
| CVE-2014-6125 | — | — | 1.0% | Oct 28, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hij... |
| CVE-2014-4821 | — | — | 2.1% | Oct 28, 2014 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0... |
| CVE-2014-4814 | — | — | 1.6% | Oct 28, 2014 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0... |
| CVE-2014-4808 | — | — | 2.6% | Oct 28, 2014 | Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.... |
| CVE-2014-3293 | — | — | 1.7% | Oct 28, 2014 | Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows... |
| CVE-2014-8506 | — | — | 1.8% | Oct 28, 2014 | Multiple SQL injection vulnerabilities in Etiko CMS allow remote attackers to execute arbitrary SQL commands via the (1)... |
| CVE-2014-8505 | — | — | 1.4% | Oct 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Etiko CMS allow remote attackers to inject arbitrary web script o... |
| CVE-2014-4023 | — | — | 1.8% | Oct 28, 2014 | Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in the Configuration utility in F5 BIG-IP LTM, APM, ... |
| CVE-2014-4586 | — | — | 1.6% | Oct 27, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the wp-football plugin 1.1 and earlier for WordPress allow remote... |
| CVE-2014-8327 | — | — | 1.1% | Oct 27, 2014 | The fal_sftp extension before 0.2.6 for TYPO3 uses weak permissions for sFTP driver files and folders, which allows remo... |
| CVE-2014-3955 | — | — | 1.6% | Oct 27, 2014 | routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemo... |
| CVE-2014-3954 | — | — | 3.9% | Oct 27, 2014 | Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of servi... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now