2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-0786Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via S...
CVE-2014-2260Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows ...
CVE-2014-3135Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 5.1.1 Alpha 9 allow remote attackers to inject arbitrar...
CVE-2014-3134Cross-site scripting (XSS) vulnerability in the InfoView application in SAP BusinessObjects allows remote attackers to i...
CVE-2014-3133SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the lis...
CVE-2014-3132SAP Background Processing does not properly restrict access, which allows remote authenticated users to obtain sensitive...
CVE-2014-3131SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive i...
CVE-2014-3130The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does no...
CVE-2014-3129The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensiti...
CVE-2014-2565The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to ...
CVE-2014-1957FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.
CVE-2014-1956CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP header...
CVE-2014-1955Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary...
CVE-2014-0471Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17....
CVE-2014-0470super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows loc...
CVE-2014-2545TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot b...
CVE-2014-2186Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attack...
CVE-2014-1528The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Wind...
CVE-2014-1527Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that...
CVE-2014-1526The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote atta...
CVE-2014-1525The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly ...
CVE-2014-1522The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0...
CVE-2014-1520maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x be...
CVE-2014-1519Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allo...
CVE-2014-0364The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now