2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4040 | — | — | 1.8% | Jun 17, 2014 | snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passw... |
| CVE-2014-4039 | — | — | 0.4% | Jun 17, 2014 | ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsna... |
| CVE-2014-4038 | — | — | 0.4% | Jun 17, 2014 | ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_supp... |
| CVE-2014-4190 | — | — | 1.5% | Jun 17, 2014 | Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S930... |
| CVE-2014-4189 | — | — | 1.2% | Jun 17, 2014 | Cross-site scripting (XSS) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Perfo... |
| CVE-2014-4188 | — | — | 0.6% | Jun 17, 2014 | Cross-site request forgery (CSRF) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP... |
| CVE-2014-4187 | — | — | 1.4% | Jun 17, 2014 | Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket allows remote attackers to inject arbitrary web scr... |
| CVE-2014-4048 | — | — | 2.8% | Jun 17, 2014 | The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (dea... |
| CVE-2014-4047 | — | — | 4.9% | Jun 17, 2014 | Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 be... |
| CVE-2014-4046 | — | — | 5.7% | Jun 17, 2014 | Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows rem... |
| CVE-2014-4045 | — | — | 2.8% | Jun 17, 2014 | The Publish/Subscribe Framework in the PJSIP channel driver in Asterisk Open Source 12.x before 12.3.1, when sub_min_exp... |
| CVE-2014-4044 | — | — | 1.6% | Jun 17, 2014 | OpenAFS 1.6.8 does not properly clear the fields in the host structure, which allows remote attackers to cause a denial ... |
| CVE-2014-3476 | — | — | 2.3% | Jun 17, 2014 | OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle c... |
| CVE-2014-3249 | — | — | 1.8% | Jun 17, 2014 | Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hidin... |
| CVE-2014-0478 | — | — | 1.6% | Jun 17, 2014 | APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and in... |
| CVE-2014-4166 | — | — | 3.2% | Jun 16, 2014 | Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject a... |
| CVE-2014-4165 | — | — | 2.1% | Jun 16, 2014 | Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the ... |
| CVE-2014-4164 | — | — | 1.0% | Jun 16, 2014 | Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230 allows remote attackers to inject arbitrary web sc... |
| CVE-2014-4163 | — | — | 2.3% | Jun 16, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow rem... |
| CVE-2014-4162 | — | — | 2.6% | Jun 16, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote att... |
| CVE-2014-3995 | — | — | 2.1% | Jun 16, 2014 | Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x befor... |
| CVE-2014-3994 | — | — | 2.4% | Jun 16, 2014 | Cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x before 0.... |
| CVE-2014-3428 | — | — | 1.9% | Jun 16, 2014 | Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to injec... |
| CVE-2014-2004 | — | — | 2.1% | Jun 16, 2014 | The PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 routers 1.00 through 3.10, SEIL/X1 routers 1.00 through 4.50, SEIL/... |
| CVE-2014-2003 | — | — | 3.6% | Jun 16, 2014 | JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatur... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now