2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2522 | — | — | 2.6% | Apr 18, 2014 | curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not veri... |
| CVE-2014-2289 | — | — | 2.2% | Apr 18, 2014 | res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authent... |
| CVE-2014-2288 | — | — | 4.3% | Apr 18, 2014 | The PJSIP channel driver in Asterisk Open Source 12.x before 12.1.1, when qualify_frequency "is enabled on an AOR and th... |
| CVE-2014-2287 | — | — | 2.4% | Apr 18, 2014 | channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and C... |
| CVE-2014-2286 | — | — | 16.3% | Apr 18, 2014 | main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified... |
| CVE-2014-2014 | — | — | 1.5% | Apr 18, 2014 | imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification fa... |
| CVE-2014-2856 | — | — | 1.6% | Apr 18, 2014 | Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows... |
| CVE-2014-2844 | — | — | 1.0% | Apr 18, 2014 | Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote auth... |
| CVE-2014-0150 | — | — | 0.7% | Apr 18, 2014 | Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest... |
| CVE-2014-2880 | — | — | 8.4% | Apr 17, 2014 | Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.... |
| CVE-2014-2879 | — | — | 4.8% | Apr 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote auth... |
| CVE-2014-2707 | — | — | 1.2% | Apr 17, 2014 | cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell met... |
| CVE-2014-2469 | — | — | 1.9% | Apr 17, 2014 | Unspecified vulnerability in lighttpd in Oracle Solaris 11.1 allows attackers to cause a denial of service via unknown v... |
| CVE-2014-2310 | — | — | 2.0% | Apr 17, 2014 | The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a mu... |
| CVE-2014-1933 | — | — | 0.4% | Apr 17, 2014 | The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow ... |
| CVE-2014-1932 | — | — | 0.5% | Apr 17, 2014 | The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in I... |
| CVE-2014-0984 | — | — | 2.8% | Apr 17, 2014 | The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation ... |
| CVE-2014-0111 | — | — | 3.3% | Apr 17, 2014 | Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via... |
| CVE-2014-0085 | — | — | 0.4% | Apr 17, 2014 | JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive info... |
| CVE-2014-0071 | — | — | 1.8% | Apr 17, 2014 | PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows r... |
| CVE-2014-0054 | — | — | 91.4% | Apr 17, 2014 | The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not ... |
| CVE-2014-0036 | — | — | 2.0% | Apr 17, 2014 | The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote atta... |
| CVE-2014-0645 | — | — | 0.3% | Apr 17, 2014 | EMC Cloud Tiering Appliance (CTA) 9.x through 10 SP1 and File Management Appliance (FMA) 7.x store DES password hashes f... |
| CVE-2014-0644 | — | — | 53.3% | Apr 17, 2014 | EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login reques... |
| CVE-2014-2338 | — | — | 1.6% | Apr 16, 2014 | IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1)... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now