2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3711namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vecto...
CVE-2014-2988EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupwa...
CVE-2014-0136The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remo...
CVE-2014-6635Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows remote attackers to inject arbitrary web script or...
CVE-2014-5520SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via ...
CVE-2014-5148Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns...
CVE-2014-3520OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticate...
CVE-2014-6037Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8...
CVE-2014-6133IBM API Management 3.x before 3.0.1.0 allows local users to obtain sensitive ciphertext information via unspecified vect...
CVE-2014-6099The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechan...
CVE-2014-4812The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, whi...
CVE-2014-2987Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGro...
CVE-2014-3137Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, whic...
CVE-2014-0476The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a...
CVE-2014-5075The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify t...
CVE-2014-1929python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "op...
CVE-2014-1928The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attac...
CVE-2014-1927The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers...
CVE-2014-3636D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prev...
CVE-2014-6611The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and b...
CVE-2014-6152Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Integrated Portal (TIP) 2.2.x allow remote authenticat...
CVE-2014-6151CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arb...
CVE-2014-4624EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authenticatio...
CVE-2014-4623EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Ha...
CVE-2014-4620The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, st...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now