2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2014-125005MEDIUM5.5A vulnerability, which was classified as problematic, was found in FFmpeg 2.0. This affects the function decode_vol_head...
CVE-2014-125004MEDIUM5.5A vulnerability has been found in FFmpeg 2.0 and classified as problematic. This vulnerability affects the function deco...
CVE-2014-125003MEDIUM5.5A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function get_siz of the fi...
CVE-2014-125002MEDIUM5.5A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function dnxhd_init_rc o...
CVE-2014-8597MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary w...
CVE-2014-10402MEDIUM6.1An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other th...
CVE-2014-10401MEDIUM6.1An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other tha...
CVE-2014-1422MEDIUM5In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the a...
CVE-2014-8944MEDIUM5.4Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config insta...
CVE-2014-8940MEDIUM5.3Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by v...
CVE-2014-8939MEDIUM5.3Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/pl...
CVE-2014-7174MEDIUM5.3FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.
CVE-2014-1423MEDIUM5.5signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from quer...
CVE-2014-7951MEDIUM4.6Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate att...
CVE-2014-4659MEDIUM5.5Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credentia...
CVE-2014-4658MEDIUM5.5The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, whic...
CVE-2014-4660MEDIUM5.5Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list,...
CVE-2014-9617MEDIUM6.1Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to re...
CVE-2014-9615MEDIUM6.1Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or H...
CVE-2014-9609MEDIUM5.3Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0...
CVE-2014-9608MEDIUM6.1Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x bef...
CVE-2014-9607MEDIUM6.1Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote...
CVE-2014-9606MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4....
CVE-2014-1617MEDIUM6.5Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of ser...
CVE-2014-8128MEDIUM6.5LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attack...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now