2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2053 | — | — | 4.7% | Jun 4, 2014 | getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read ... |
| CVE-2014-3956 | — | — | 0.6% | Jun 4, 2014 | The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently ski... |
| CVE-2014-0935 | — | — | 0.7% | Jun 4, 2014 | Unspecified vulnerability in IBM Smart Analytics System 7700 before FP 2.1.3.0 and 7710 before FP 2.1.3.0 allows local u... |
| CVE-2014-2502 | — | — | 2.0% | Jun 4, 2014 | Cross-site scripting (XSS) vulnerability in rsa_fso.swf in EMC RSA Adaptive Authentication (Hosted) 11.0 allows remote a... |
| CVE-2014-3959 | — | — | 1.5% | Jun 3, 2014 | Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM,... |
| CVE-2014-3946 | — | — | 1.1% | Jun 3, 2014 | The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validat... |
| CVE-2014-3945 | — | — | 1.6% | Jun 3, 2014 | The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowle... |
| CVE-2014-3944 | — | — | 1.3% | Jun 3, 2014 | The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which all... |
| CVE-2014-3943 | — | — | 1.4% | Jun 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 4.5.0 before 4.5.34, 4.7.... |
| CVE-2014-3942 | — | — | 1.6% | Jun 3, 2014 | The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 befo... |
| CVE-2014-3941 | — | — | 2.7% | Jun 3, 2014 | TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows r... |
| CVE-2014-3466 | — | — | 11.3% | Jun 3, 2014 | Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15... |
| CVE-2014-3280 | — | — | 2.0% | Jun 3, 2014 | The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly imp... |
| CVE-2014-2959 | — | — | 3.0% | Jun 2, 2014 | logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i5... |
| CVE-2014-2946 | — | — | 1.1% | Jun 2, 2014 | Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems... |
| CVE-2014-2939 | — | — | 1.0% | Jun 2, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise before 4.1.6.13 allow remote attackers to inj... |
| CVE-2014-3937 | — | — | 2.0% | Jun 2, 2014 | SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers... |
| CVE-2014-0042 | — | — | 1.5% | Jun 2, 2014 | OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets gpgcheck to ... |
| CVE-2014-0041 | — | — | 1.4% | Jun 2, 2014 | OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets sslverify to... |
| CVE-2014-0040 | — | — | 1.5% | Jun 2, 2014 | OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, uses an HTTP conn... |
| CVE-2014-3936 | — | — | 76.6% | Jun 2, 2014 | Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06... |
| CVE-2014-3935 | — | — | 2.1% | Jun 2, 2014 | SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut... |
| CVE-2014-3934 | — | — | 2.2% | Jun 2, 2014 | SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL ... |
| CVE-2014-3933 | — | — | 0.9% | Jun 2, 2014 | Cross-site scripting (XSS) vulnerability in the address components field formatter in the AddressField Tokens module 7.x... |
| CVE-2014-3932 | — | — | 1.2% | Jun 2, 2014 | SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now