2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4913 | MEDIUM | 6.1 | 1.2% | Dec 15, 2019 | ZF2014-03 has a potential cross site scripting vector in multiple view helpers |
| CVE-2014-3701 | HIGH | 8.1 | 1.5% | Dec 15, 2019 | eDeploy has tmp file race condition flaws |
| CVE-2014-3699 | CRITICAL | 9.8 | 2.3% | Dec 15, 2019 | eDeploy has RCE via cPickle deserialization of untrusted data |
| CVE-2014-3652 | MEDIUM | 6.1 | 0.7% | Dec 15, 2019 | JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL. |
| CVE-2014-3643 | HIGH | 7.5 | 2.1% | Dec 15, 2019 | jersey: XXE via parameter entities not disabled by the jersey SAX parser |
| CVE-2014-3536 | MEDIUM | 5.5 | 0.3% | Dec 15, 2019 | CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration |
| CVE-2014-3495 | HIGH | 7.5 | 0.9% | Dec 13, 2019 | duplicity 0.6.24 has improper verification of SSL certificates |
| CVE-2014-2387 | MEDIUM | 4.4 | 0.4% | Dec 13, 2019 | Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities |
| CVE-2014-1867 | HIGH | 7.8 | 0.4% | Dec 13, 2019 | suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution |
| CVE-2014-0241 | MEDIUM | 5.5 | 0.3% | Dec 13, 2019 | rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable |
| CVE-2014-0212 | HIGH | 7.5 | 3.5% | Dec 13, 2019 | qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descrip... |
| CVE-2014-0197 | HIGH | 8.8 | 0.7% | Dec 13, 2019 | CFME: CSRF protection vulnerability via permissive check of the referrer header |
| CVE-2014-0175 | CRITICAL | 9.8 | 2.0% | Dec 13, 2019 | mcollective has a default password set at install |
| CVE-2014-7257 | CRITICAL | 9.8 | 1.6% | Dec 11, 2019 | SQL injection vulnerability in DBD::PgPP 0.05 and earlier |
| CVE-2014-0163 | HIGH | 8.8 | 2.0% | Dec 11, 2019 | Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. |
| CVE-2014-0091 | MEDIUM | 5.3 | 1.6% | Dec 11, 2019 | Foreman has improper input validation which could lead to partial Denial of Service |
| CVE-2014-0026 | MEDIUM | 6.5 | 0.4% | Dec 11, 2019 | katello-headpin is vulnerable to CSRF in REST API |
| CVE-2014-3656 | MEDIUM | 6.1 | 0.7% | Dec 10, 2019 | JBoss KeyCloak: XSS in login-status-iframe.html |
| CVE-2014-0242 | HIGH | 7.5 | 8.5% | Dec 9, 2019 | mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info... |
| CVE-2014-9356 | HIGH | 8.6 | 4.9% | Dec 2, 2019 | Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a con... |
| CVE-2014-3591 | MEDIUM | 4.2 | 0.6% | Nov 29, 2019 | Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allo... |
| CVE-2014-3875 | MEDIUM | 6.1 | 1.7% | Nov 27, 2019 | The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to co... |
| CVE-2014-6311 | CRITICAL | 9.8 | 1.7% | Nov 22, 2019 | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attacker... |
| CVE-2014-6310 | CRITICAL | 9.8 | 4.7% | Nov 22, 2019 | Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' funct... |
| CVE-2014-2214 | MEDIUM | 6.1 | 0.8% | Nov 22, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now