2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-0349Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 20...
CVE-2014-0347The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31...
CVE-2014-1210VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which a...
CVE-2014-1209VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Clien...
CVE-2014-0636EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certi...
CVE-2014-1969Directory traversal vulnerability in the apps4u@android SD Card Manager application before 20140224 for Android allows a...
CVE-2014-0777The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers ...
CVE-2014-2850The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator...
CVE-2014-2849The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users ...
CVE-2014-2848A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain pri...
CVE-2014-2847SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands ...
CVE-2014-0172Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and ...
CVE-2014-2540SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitra...
CVE-2014-2333Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attacke...
CVE-2014-1985Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Red...
CVE-2014-2829Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, w...
CVE-2014-2746net/IOService.java in Tigase before 5.2.1 does not properly restrict the processing of compressed XML elements, which al...
CVE-2014-2745Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers...
CVE-2014-2744plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compr...
CVE-2014-2743plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed ...
CVE-2014-2742Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote att...
CVE-2014-2741nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of comp...
CVE-2014-0920IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authentic...
CVE-2014-0908The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, an...
CVE-2014-2752SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote att...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now