2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2732 | — | — | 3.6% | Apr 19, 2014 | Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow r... |
| CVE-2014-2731 | — | — | 4.2% | Apr 19, 2014 | Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote at... |
| CVE-2014-1990 | — | — | 1.1% | Apr 19, 2014 | Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Stu... |
| CVE-2014-1984 | — | — | 1.7% | Apr 19, 2014 | Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.... |
| CVE-2014-1983 | — | — | 2.3% | Apr 19, 2014 | Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to... |
| CVE-2014-1974 | — | — | 1.5% | Apr 19, 2014 | Directory traversal vulnerability in the LYSESOFT AndExplorer application before 20140403 and AndExplorerPro application... |
| CVE-2014-0778 | — | — | 1.3% | Apr 19, 2014 | TCPUploader module listens on Port 10651/TCP for incoming connections. Exploitation of this vulnerability could allow a... |
| CVE-2014-2597 | — | — | 0.3% | Apr 18, 2014 | PCNetSoftware RAC Server 4.0.4 and 4.0.5 allows local users to cause a denial of service (disabled keyboard or crash) vi... |
| CVE-2014-2522 | — | — | 2.6% | Apr 18, 2014 | curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not veri... |
| CVE-2014-2289 | — | — | 2.2% | Apr 18, 2014 | res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authent... |
| CVE-2014-2288 | — | — | 4.3% | Apr 18, 2014 | The PJSIP channel driver in Asterisk Open Source 12.x before 12.1.1, when qualify_frequency "is enabled on an AOR and th... |
| CVE-2014-2287 | — | — | 2.4% | Apr 18, 2014 | channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and C... |
| CVE-2014-2286 | — | — | 16.3% | Apr 18, 2014 | main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified... |
| CVE-2014-2014 | — | — | 1.5% | Apr 18, 2014 | imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification fa... |
| CVE-2014-2856 | — | — | 1.6% | Apr 18, 2014 | Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows... |
| CVE-2014-2844 | — | — | 1.0% | Apr 18, 2014 | Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote auth... |
| CVE-2014-0150 | — | — | 0.7% | Apr 18, 2014 | Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest... |
| CVE-2014-2880 | — | — | 8.4% | Apr 17, 2014 | Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.... |
| CVE-2014-2879 | — | — | 4.8% | Apr 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote auth... |
| CVE-2014-2707 | — | — | 1.2% | Apr 17, 2014 | cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell met... |
| CVE-2014-2469 | — | — | 1.9% | Apr 17, 2014 | Unspecified vulnerability in lighttpd in Oracle Solaris 11.1 allows attackers to cause a denial of service via unknown v... |
| CVE-2014-2310 | — | — | 2.0% | Apr 17, 2014 | The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a mu... |
| CVE-2014-1933 | — | — | 0.4% | Apr 17, 2014 | The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow ... |
| CVE-2014-1932 | — | — | 0.5% | Apr 17, 2014 | The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in I... |
| CVE-2014-0984 | — | — | 2.8% | Apr 17, 2014 | The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now