2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0243Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_m...
CVE-2014-2079X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary fi...
CVE-2014-5220The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize devic...
CVE-2014-0594HIGH8.8In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, a...
CVE-2014-0593HIGH7.8The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). I...
CVE-2014-10066HIGH7.5Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacke...
CVE-2014-10065Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript:...
CVE-2014-10064The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string repr...
CVE-2014-10068HIGH7.5The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, ev...
CVE-2014-10067paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it shou...
CVE-2014-2552Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, ...
CVE-2014-1846Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.
CVE-2014-1845An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging fai...
CVE-2014-0841IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it ea...
CVE-2014-0882Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might...
CVE-2014-0881The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows...
CVE-2014-0872The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow loc...
CVE-2014-5014The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via...
CVE-2014-0950Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQues...
CVE-2014-0931Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration tr...
CVE-2014-0927The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow...
CVE-2014-0912IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive...
CVE-2014-0900The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and conseq...
CVE-2014-0883IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2014-6112IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now