2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1996 | — | — | 2.6% | Jul 20, 2014 | Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbit... |
| CVE-2014-1995 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 all... |
| CVE-2014-1994 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remot... |
| CVE-2014-1993 | — | — | 1.1% | Jul 20, 2014 | The Portlets subsystem in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to bypass intended ... |
| CVE-2014-1992 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the Messages functionality in Cybozu Garoon 3.1.x, 3.5.x, and 3.7.x before 3... |
| CVE-2014-1987 | — | — | 3.2% | Jul 20, 2014 | The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspe... |
| CVE-2014-1973 | — | — | 1.9% | Jul 20, 2014 | Directory traversal vulnerability in the NextApp File Explorer application before 2.1.0.3 for Android allows remote atta... |
| CVE-2014-0231 | — | — | 43.8% | Jul 20, 2014 | The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attac... |
| CVE-2014-0226 | — | — | 85.7% | Jul 20, 2014 | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denia... |
| CVE-2014-0118 | — | — | 37.2% | Jul 20, 2014 | The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when ... |
| CVE-2014-0117 | — | — | 35.5% | Jul 20, 2014 | The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attac... |
| CVE-2014-4331 | — | — | 1.9% | Jul 19, 2014 | Cross-site scripting (XSS) vulnerability in admin/viewer.php in OctavoCMS allows remote attackers to inject arbitrary we... |
| CVE-2014-4943 | — | — | 2.1% | Jul 19, 2014 | The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by ... |
| CVE-2014-3533 | — | — | 0.4% | Jul 19, 2014 | dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certa... |
| CVE-2014-3532 | — | — | 0.4% | Jul 19, 2014 | dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause ... |
| CVE-2014-3325 | — | — | 1.4% | Jul 19, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Customer Voice Portal (CVP) allow remote attackers ... |
| CVE-2014-2519 | — | — | 1.7% | Jul 19, 2014 | The default configuration of EMC RecoverPoint Appliance (RPA) 4.1 before 4.1.0.1 does not enable a firewall, which allow... |
| CVE-2014-3064 | — | — | 1.1% | Jul 19, 2014 | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and Inf... |
| CVE-2014-3045 | — | — | 0.3% | Jul 19, 2014 | IBM Scale Out Network Attached Storage (SONAS) 1.3.x and 1.4.x before 1.4.3.3 places an administrative password in the s... |
| CVE-2014-3043 | — | — | 1.5% | Jul 19, 2014 | IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by levera... |
| CVE-2014-2368 | — | — | 1.7% | Jul 19, 2014 | The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to rea... |
| CVE-2014-2367 | — | — | 1.5% | Jul 19, 2014 | The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows... |
| CVE-2014-2366 | — | — | 1.3% | Jul 19, 2014 | upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTM... |
| CVE-2014-2365 | — | — | 1.6% | Jul 19, 2014 | Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitr... |
| CVE-2014-2364 | — | — | 61.4% | Jul 19, 2014 | Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now