2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2014-1958HIGH8.8Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attacke...
CVE-2014-8141HIGH7.8Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to exe...
CVE-2014-8321HIGH7.8Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local use...
CVE-2014-8140HIGH7.8Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to ex...
CVE-2014-8139HIGH7.8Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execut...
CVE-2014-8126HIGH8.8The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.
CVE-2014-5236HIGH7.5Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 a...
CVE-2014-3868HIGH8.8Multiple SQL injection vulnerabilities in ZeusCart 4.x.
CVE-2014-3119HIGH8.8Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitr...
CVE-2014-3856HIGH7The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows ...
CVE-2014-2906HIGH7The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows lo...
CVE-2014-2581HIGH7.5Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Addition...
CVE-2014-8742HIGH7.5Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allow...
CVE-2014-7303HIGH7.8SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain pas...
CVE-2014-7302HIGH7.8SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the...
CVE-2014-3979HIGH7.5Bytemark Symbiosis allows remote attackers to cause a denial of service via a crafted username, which triggers the firew...
CVE-2014-9630HIGH7.8The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a s...
CVE-2014-9629HIGH7.8Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2....
CVE-2014-9628HIGH7.8The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote at...
CVE-2014-9627HIGH7.8The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an inco...
CVE-2014-9626HIGH7.8Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2...
CVE-2014-9625HIGH7.8The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorre...
CVE-2014-1923HIGH7.5Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picuploa...
CVE-2014-1922HIGH7.5Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before ...
CVE-2014-2680HIGH8.1The update process in Xmind 3.4.1 and earlier allow remote attackers to execute arbitrary code via a man-in-the-middle a...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now