2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4913MEDIUM6.1ZF2014-03 has a potential cross site scripting vector in multiple view helpers
CVE-2014-3701HIGH8.1eDeploy has tmp file race condition flaws
CVE-2014-3699CRITICAL9.8eDeploy has RCE via cPickle deserialization of untrusted data
CVE-2014-3652MEDIUM6.1JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
CVE-2014-3643HIGH7.5jersey: XXE via parameter entities not disabled by the jersey SAX parser
CVE-2014-3536MEDIUM5.5CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
CVE-2014-3495HIGH7.5duplicity 0.6.24 has improper verification of SSL certificates
CVE-2014-2387MEDIUM4.4Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
CVE-2014-1867HIGH7.8suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution
CVE-2014-0241MEDIUM5.5rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
CVE-2014-0212HIGH7.5qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descrip...
CVE-2014-0197HIGH8.8CFME: CSRF protection vulnerability via permissive check of the referrer header
CVE-2014-0175CRITICAL9.8mcollective has a default password set at install
CVE-2014-7257CRITICAL9.8SQL injection vulnerability in DBD::PgPP 0.05 and earlier
CVE-2014-0163HIGH8.8Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
CVE-2014-0091MEDIUM5.3Foreman has improper input validation which could lead to partial Denial of Service
CVE-2014-0026MEDIUM6.5katello-headpin is vulnerable to CSRF in REST API
CVE-2014-3656MEDIUM6.1JBoss KeyCloak: XSS in login-status-iframe.html
CVE-2014-0242HIGH7.5mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info...
CVE-2014-9356HIGH8.6Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a con...
CVE-2014-3591MEDIUM4.2Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allo...
CVE-2014-3875MEDIUM6.1The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to co...
CVE-2014-6311CRITICAL9.8generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attacker...
CVE-2014-6310CRITICAL9.8Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' funct...
CVE-2014-2214MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now