2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-7952The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execu...
CVE-2014-6437Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configurat...
CVE-2014-6436Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to...
CVE-2014-6435cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,...
CVE-2014-3471Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial...
CVE-2014-5070HIGH8.8Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenti...
CVE-2014-5068HIGH7.5Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read ar...
CVE-2014-0087The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms...
CVE-2014-5004lib/brbackup.rb in the brbackup gem 0.1.1 for Ruby places the database password on the mysql command line, which allows ...
CVE-2014-5003chef/travis-cookbooks/ci_environment/perlbrew/recipes/default.rb in the ciborg gem 3.0.0 for Ruby allows local users to ...
CVE-2014-5002The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain s...
CVE-2014-5001lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (...
CVE-2014-5000The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, whic...
CVE-2014-4999vendor/plugins/dataset/lib/dataset/database/mysql.rb in the kajam gem 1.0.3.rc2 for Ruby places the mysql user password ...
CVE-2014-4998test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, ...
CVE-2014-4997lib/commands/setup.rb in the point-cli gem 0.0.1 for Ruby places credentials on the curl command line, which allows loca...
CVE-2014-4996lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a s...
CVE-2014-4995Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensiti...
CVE-2014-4994lib/gyazo/client.rb in the gyazo gem 1.0.0 for Ruby allows local users to write to arbitrary files via a symlink attack ...
CVE-2014-4993(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum...
CVE-2014-4992lib/cap-strap/helpers.rb in the cap-strap gem 0.1.5 for Ruby places credentials on the useradd command line, which allow...
CVE-2014-4991(1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby...
CVE-2014-7222Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (a...
CVE-2014-7221TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and ...
CVE-2014-5509clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clip...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now