2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0198 | — | — | 43.8% | May 6, 2014 | The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not... |
| CVE-2014-0185 | — | — | 0.5% | May 6, 2014 | sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 perm... |
| CVE-2014-3220 | — | — | 11.0% | May 5, 2014 | F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary u... |
| CVE-2014-0164 | — | — | 0.4% | May 5, 2014 | openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions f... |
| CVE-2014-0149 | — | — | 1.0% | May 5, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to i... |
| CVE-2014-2916 | — | — | 1.1% | May 5, 2014 | Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allo... |
| CVE-2014-0469 | — | — | 3.4% | May 5, 2014 | Stack-based buffer overflow in a certain Debian patch for xbuffy before 3.3.bl.3.dfsg-9 allows remote attackers to execu... |
| CVE-2014-3125 | — | — | 0.6% | May 2, 2014 | Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local ... |
| CVE-2014-3006 | — | — | 1.3% | May 2, 2014 | Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly ... |
| CVE-2014-3001 | — | — | 1.0% | May 2, 2014 | The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows c... |
| CVE-2014-3000 | — | — | 12.8% | May 2, 2014 | The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, ... |
| CVE-2014-2905 | — | — | 0.4% | May 2, 2014 | fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain priv... |
| CVE-2014-2322 | — | — | 2.2% | May 2, 2014 | lib/string_utf_support.rb in the Arabic Prawn 0.0.1 gem for Ruby allows remote attackers to execute arbitrary commands v... |
| CVE-2014-1899 | — | — | 1.2% | May 2, 2014 | Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition)... |
| CVE-2014-0189 | — | — | 0.4% | May 2, 2014 | virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hy... |
| CVE-2014-3139 | — | — | 3.3% | May 2, 2014 | recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by s... |
| CVE-2014-2175 | — | — | 1.3% | May 2, 2014 | Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allow remote attackers to cause a denial of servi... |
| CVE-2014-2173 | — | — | 0.4% | May 2, 2014 | Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial por... |
| CVE-2014-2172 | — | — | 0.3% | May 2, 2014 | Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain pri... |
| CVE-2014-2171 | — | — | 3.6% | May 2, 2014 | Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x ... |
| CVE-2014-2170 | — | — | 2.2% | May 2, 2014 | Cisco TelePresence TC Software 4.x and 5.x before 5.1.7 and 6.x before 6.0.1 and TE Software 4.x and 6.0 allow remote au... |
| CVE-2014-2169 | — | — | 2.1% | May 2, 2014 | Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users... |
| CVE-2014-2168 | — | — | 2.8% | May 2, 2014 | Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to exe... |
| CVE-2014-2167 | — | — | 1.3% | May 2, 2014 | The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers... |
| CVE-2014-2166 | — | — | 1.3% | May 2, 2014 | The SIP implementation in Cisco TelePresence TC Software 4.x and TE Software 4.x allows remote attackers to cause a deni... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now