2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3945 | — | — | 1.6% | Jun 3, 2014 | The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowle... |
| CVE-2014-3944 | — | — | 1.3% | Jun 3, 2014 | The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which all... |
| CVE-2014-3943 | — | — | 1.4% | Jun 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 4.5.0 before 4.5.34, 4.7.... |
| CVE-2014-3942 | — | — | 1.6% | Jun 3, 2014 | The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 befo... |
| CVE-2014-3941 | — | — | 2.7% | Jun 3, 2014 | TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows r... |
| CVE-2014-3466 | — | — | 11.3% | Jun 3, 2014 | Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15... |
| CVE-2014-3280 | — | — | 2.0% | Jun 3, 2014 | The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly imp... |
| CVE-2014-2959 | — | — | 3.0% | Jun 2, 2014 | logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i5... |
| CVE-2014-2946 | — | — | 1.1% | Jun 2, 2014 | Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems... |
| CVE-2014-2939 | — | — | 1.0% | Jun 2, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise before 4.1.6.13 allow remote attackers to inj... |
| CVE-2014-3937 | — | — | 2.0% | Jun 2, 2014 | SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers... |
| CVE-2014-0042 | — | — | 1.5% | Jun 2, 2014 | OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets gpgcheck to ... |
| CVE-2014-0041 | — | — | 1.4% | Jun 2, 2014 | OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets sslverify to... |
| CVE-2014-0040 | — | — | 1.5% | Jun 2, 2014 | OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, uses an HTTP conn... |
| CVE-2014-3936 | — | — | 76.6% | Jun 2, 2014 | Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06... |
| CVE-2014-3935 | — | — | 2.1% | Jun 2, 2014 | SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut... |
| CVE-2014-3934 | — | — | 2.2% | Jun 2, 2014 | SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL ... |
| CVE-2014-3933 | — | — | 0.9% | Jun 2, 2014 | Cross-site scripting (XSS) vulnerability in the address components field formatter in the AddressField Tokens module 7.x... |
| CVE-2014-3932 | — | — | 1.2% | Jun 2, 2014 | SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4... |
| CVE-2014-3925 | — | — | 2.2% | Jun 1, 2014 | sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file pot... |
| CVE-2014-3790 | — | — | 2.4% | Jun 1, 2014 | Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary com... |
| CVE-2014-0238 | — | — | 20.8% | Jun 1, 2014 | The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allo... |
| CVE-2014-0237 | — | — | 19.9% | Jun 1, 2014 | The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 all... |
| CVE-2014-3793 | — | — | 1.1% | May 31, 2014 | VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, a... |
| CVE-2014-0119 | — | — | 7.6% | May 31, 2014 | Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that a... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now