2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3925 | — | — | 2.2% | Jun 1, 2014 | sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file pot... |
| CVE-2014-3790 | — | — | 2.4% | Jun 1, 2014 | Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary com... |
| CVE-2014-0238 | — | — | 20.8% | Jun 1, 2014 | The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allo... |
| CVE-2014-0237 | — | — | 19.9% | Jun 1, 2014 | The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 all... |
| CVE-2014-3793 | — | — | 1.1% | May 31, 2014 | VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, a... |
| CVE-2014-0119 | — | — | 7.6% | May 31, 2014 | Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that a... |
| CVE-2014-0099 | — | — | 8.8% | May 31, 2014 | Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.... |
| CVE-2014-0096 | — | — | 6.9% | May 31, 2014 | java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before ... |
| CVE-2014-0095 | — | — | 8.5% | May 31, 2014 | java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause ... |
| CVE-2014-0075 | — | — | 20.1% | May 31, 2014 | Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Ap... |
| CVE-2014-2354 | — | — | 0.7% | May 30, 2014 | Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent att... |
| CVE-2014-2353 | — | — | 2.5% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web ... |
| CVE-2014-2352 | — | — | 2.3% | May 30, 2014 | The directory specifier can include designators that can be used to traverse the directory path. Exploiting this vulner... |
| CVE-2014-2343 | — | — | 0.3% | May 30, 2014 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of servi... |
| CVE-2014-2342 | — | — | 1.8% | May 30, 2014 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive ... |
| CVE-2014-0907 | — | — | 0.7% | May 30, 2014 | Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 bef... |
| CVE-2014-0925 | — | — | 1.1% | May 30, 2014 | Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 a... |
| CVE-2014-3865 | — | — | 7.3% | May 30, 2014 | Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files out... |
| CVE-2014-3864 | — | — | 2.8% | May 30, 2014 | Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of th... |
| CVE-2014-3227 | — | — | 1.8% | May 30, 2014 | dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for th... |
| CVE-2014-3010 | — | — | 1.2% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 ... |
| CVE-2014-3924 | — | — | 1.4% | May 30, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attacke... |
| CVE-2014-3923 | — | — | 1.6% | May 30, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress ... |
| CVE-2014-3922 | — | — | 2.1% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.1516 allows... |
| CVE-2014-3921 | — | — | 1.6% | May 30, 2014 | Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote atta... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now