2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-4007The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access vi...
CVE-2014-4006The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for ...
CVE-2014-4005SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified...
CVE-2014-4004The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, whic...
CVE-2014-4003The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related ...
CVE-2014-3977libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on...
CVE-2014-3048Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges b...
CVE-2014-3038IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypas...
CVE-2014-3036Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attac...
CVE-2014-0936IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the c...
CVE-2014-0929Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows ...
CVE-2014-3986include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a...
CVE-2014-3982include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink atta...
CVE-2014-3981acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files...
CVE-2014-0961Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before...
CVE-2014-3291Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereferenc...
CVE-2014-3286The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows r...
CVE-2014-3281The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access contro...
CVE-2014-3278The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access contro...
CVE-2014-2508EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote a...
CVE-2014-2507EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote a...
CVE-2014-2506EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote a...
CVE-2014-3153HIGH7.8The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff...
CVE-2014-3984Multiple unspecified vulnerabilities in Libav before 0.8.12 allow remote attackers to have unknown impact and vectors.
CVE-2014-3966Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, an...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now