2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-2213MEDIUM6.1Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to red...
CVE-2014-1238MEDIUM6.1Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier.
CVE-2014-3585CRITICAL9.8redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
CVE-2014-5255HIGH7xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr...
CVE-2014-5254MEDIUM4.7xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr...
CVE-2014-2904HIGH7.5wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
CVE-2014-2902HIGH7.5wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
CVE-2014-2901HIGH7.5wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
CVE-2014-8356HIGH8.8The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a...
CVE-2014-3700CRITICAL9.8eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
CVE-2014-1938MEDIUM5.5python-rply before 0.7.4 insecurely creates temporary files.
CVE-2014-1937HIGH7.5Gamera before 3.4.1 insecurely creates temporary files.
CVE-2014-1936HIGH7.5rc before 1.7.1-5 insecurely creates temporary files.
CVE-2014-1935MEDIUM5.39base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
CVE-2014-0084MEDIUM5.5Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se...
CVE-2014-0083MEDIUM5.5The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
CVE-2014-5439HIGH7.8Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file t...
CVE-2014-5118MEDIUM5.5Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
CVE-2014-0023HIGH7.8OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
CVE-2014-0021HIGH7.5Chrony before 1.29.1 has traffic amplification in cmdmon protocol
CVE-2014-1214HIGH8.8views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attac...
CVE-2014-8167MEDIUM5.9vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle at...
CVE-2014-3655MEDIUM4.3JBoss KeyCloak is vulnerable to soft token deletion via CSRF
CVE-2014-3592MEDIUM6.1OpenShift Origin: Improperly validated team names could allow stored XSS attacks
CVE-2014-7143HIGH7.5Python Twisted 14.0 trustRoot is not respected in HTTP client

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now