2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2213 | MEDIUM | 6.1 | 1.4% | Nov 22, 2019 | Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to red... |
| CVE-2014-1238 | MEDIUM | 6.1 | 0.6% | Nov 22, 2019 | Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier. |
| CVE-2014-3585 | CRITICAL | 9.8 | 1.1% | Nov 22, 2019 | redhat-upgrade-tool: Does not check GPG signatures when upgrading versions |
| CVE-2014-5255 | HIGH | 7 | 0.4% | Nov 21, 2019 | xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr... |
| CVE-2014-5254 | MEDIUM | 4.7 | 0.3% | Nov 21, 2019 | xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr... |
| CVE-2014-2904 | HIGH | 7.5 | 0.9% | Nov 21, 2019 | wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication. |
| CVE-2014-2902 | HIGH | 7.5 | 0.8% | Nov 21, 2019 | wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates. |
| CVE-2014-2901 | HIGH | 7.5 | 0.6% | Nov 21, 2019 | wolfssl before 3.2.0 does not properly issue certificates for a server's hostname. |
| CVE-2014-8356 | HIGH | 8.8 | 5.6% | Nov 21, 2019 | The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a... |
| CVE-2014-3700 | CRITICAL | 9.8 | 2.9% | Nov 21, 2019 | eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data |
| CVE-2014-1938 | MEDIUM | 5.5 | 0.4% | Nov 21, 2019 | python-rply before 0.7.4 insecurely creates temporary files. |
| CVE-2014-1937 | HIGH | 7.5 | 1.3% | Nov 21, 2019 | Gamera before 3.4.1 insecurely creates temporary files. |
| CVE-2014-1936 | HIGH | 7.5 | 1.3% | Nov 21, 2019 | rc before 1.7.1-5 insecurely creates temporary files. |
| CVE-2014-1935 | MEDIUM | 5.3 | 1.4% | Nov 21, 2019 | 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. |
| CVE-2014-0084 | MEDIUM | 5.5 | 0.3% | Nov 21, 2019 | Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se... |
| CVE-2014-0083 | MEDIUM | 5.5 | 0.3% | Nov 21, 2019 | The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords. |
| CVE-2014-5439 | HIGH | 7.8 | 2.5% | Nov 19, 2019 | Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file t... |
| CVE-2014-5118 | MEDIUM | 5.5 | 0.4% | Nov 18, 2019 | Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability |
| CVE-2014-0023 | HIGH | 7.8 | 0.4% | Nov 15, 2019 | OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution |
| CVE-2014-0021 | HIGH | 7.5 | 3.8% | Nov 15, 2019 | Chrony before 1.29.1 has traffic amplification in cmdmon protocol |
| CVE-2014-1214 | HIGH | 8.8 | 4.3% | Nov 13, 2019 | views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attac... |
| CVE-2014-8167 | MEDIUM | 5.9 | 0.7% | Nov 13, 2019 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle at... |
| CVE-2014-3655 | MEDIUM | 4.3 | 0.5% | Nov 13, 2019 | JBoss KeyCloak is vulnerable to soft token deletion via CSRF |
| CVE-2014-3592 | MEDIUM | 6.1 | 0.7% | Nov 13, 2019 | OpenShift Origin: Improperly validated team names could allow stored XSS attacks |
| CVE-2014-7143 | HIGH | 7.5 | 2.6% | Nov 12, 2019 | Python Twisted 14.0 trustRoot is not respected in HTTP client |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now