2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2689 | — | — | 1.2% | May 8, 2014 | Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web sc... |
| CVE-2014-1934 | — | — | 0.3% | May 8, 2014 | tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files vi... |
| CVE-2014-1685 | — | — | 1.4% | May 8, 2014 | The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" ... |
| CVE-2014-1682 | — | — | 1.6% | May 8, 2014 | The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users ... |
| CVE-2014-0192 | — | — | 1.5% | May 8, 2014 | Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote atta... |
| CVE-2014-0190 | — | — | 4.0% | May 8, 2014 | The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference... |
| CVE-2014-0135 | — | — | 0.3% | May 8, 2014 | Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, ... |
| CVE-2014-0134 | — | — | 1.5% | May 8, 2014 | The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvi... |
| CVE-2014-0110 | — | — | 3.6% | May 8, 2014 | Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consump... |
| CVE-2014-0109 | — | — | 3.6% | May 8, 2014 | Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumptio... |
| CVE-2014-0090 | — | — | 1.4% | May 8, 2014 | Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id... |
| CVE-2014-0056 | — | — | 1.4% | May 8, 2014 | The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows ... |
| CVE-2014-3426 | — | — | 0.3% | May 8, 2014 | NCSA Mosaic 2.1 through 2.7b5 allows local users to cause a denial of service ("remote control" outage) by creating a /t... |
| CVE-2014-3425 | — | — | 0.3% | May 8, 2014 | NCSA Mosaic 2.0 and earlier allows local users to cause a denial of service ("remote control" outage) by creating a /tmp... |
| CVE-2014-3424 | — | — | 0.3% | May 8, 2014 | lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack ... |
| CVE-2014-3423 | — | — | 0.3% | May 8, 2014 | lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attac... |
| CVE-2014-3422 | — | — | 0.3% | May 8, 2014 | lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink a... |
| CVE-2014-3421 | — | — | 0.3% | May 8, 2014 | lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack... |
| CVE-2014-3215 | — | — | 0.4% | May 8, 2014 | seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes t... |
| CVE-2014-2936 | — | — | 1.6% | May 8, 2014 | The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope ... |
| CVE-2014-2935 | — | — | 4.4% | May 8, 2014 | costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via... |
| CVE-2014-2934 | — | — | 1.5% | May 8, 2014 | Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the ... |
| CVE-2014-2933 | — | — | 3.0% | May 8, 2014 | Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary direct... |
| CVE-2014-2602 | — | — | 2.0% | May 8, 2014 | Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privileges via unknown ve... |
| CVE-2014-2136 | — | — | 3.8% | May 8, 2014 | Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 befo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now