2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0243 | — | — | 0.6% | Jul 19, 2018 | Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_m... |
| CVE-2014-2079 | — | — | 0.4% | Jul 16, 2018 | X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary fi... |
| CVE-2014-5220 | — | — | 0.5% | Jun 8, 2018 | The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize devic... |
| CVE-2014-0594 | HIGH | 8.8 | 0.8% | Jun 8, 2018 | In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, a... |
| CVE-2014-0593 | HIGH | 7.8 | 1.9% | Jun 8, 2018 | The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). I... |
| CVE-2014-10066 | HIGH | 7.5 | 1.6% | May 31, 2018 | Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacke... |
| CVE-2014-10065 | — | — | 1.0% | May 31, 2018 | Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript:... |
| CVE-2014-10064 | — | — | 1.3% | May 31, 2018 | The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string repr... |
| CVE-2014-10068 | HIGH | 7.5 | 1.9% | May 29, 2018 | The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, ev... |
| CVE-2014-10067 | — | — | 1.2% | May 29, 2018 | paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it shou... |
| CVE-2014-2552 | — | — | 3.8% | Apr 27, 2018 | Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, ... |
| CVE-2014-1846 | — | — | 0.4% | Apr 27, 2018 | Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method. |
| CVE-2014-1845 | — | — | 0.4% | Apr 27, 2018 | An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging fai... |
| CVE-2014-0841 | — | — | 0.2% | Apr 27, 2018 | IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it ea... |
| CVE-2014-0882 | — | — | 1.2% | Apr 25, 2018 | Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might... |
| CVE-2014-0881 | — | — | 2.1% | Apr 25, 2018 | The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows... |
| CVE-2014-0872 | — | — | 0.3% | Apr 25, 2018 | The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow loc... |
| CVE-2014-5014 | — | — | 3.6% | Apr 25, 2018 | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via... |
| CVE-2014-0950 | — | — | 1.7% | Apr 20, 2018 | Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQues... |
| CVE-2014-0931 | — | — | 2.7% | Apr 20, 2018 | Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration tr... |
| CVE-2014-0927 | — | — | 2.3% | Apr 20, 2018 | The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow... |
| CVE-2014-0912 | — | — | 1.7% | Apr 20, 2018 | IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive... |
| CVE-2014-0900 | — | — | 0.5% | Apr 20, 2018 | The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and conseq... |
| CVE-2014-0883 | — | — | 0.7% | Apr 20, 2018 | IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
| CVE-2014-6112 | — | — | 1.9% | Apr 20, 2018 | IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now