2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0899 | — | — | 1.9% | Mar 11, 2014 | ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used,... |
| CVE-2014-0102 | — | — | 0.5% | Mar 11, 2014 | The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not proper... |
| CVE-2014-0100 | — | — | 3.0% | Mar 11, 2014 | Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows re... |
| CVE-2014-0101 | — | — | 7.0% | Mar 11, 2014 | The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain ... |
| CVE-2014-0049 | — | — | 0.8% | Mar 11, 2014 | Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows gu... |
| CVE-2014-2318 | — | — | 2.1% | Mar 11, 2014 | SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m p... |
| CVE-2014-0094 | — | — | 99.6% | Mar 11, 2014 | The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t... |
| CVE-2014-2317 | — | — | 1.2% | Mar 9, 2014 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ... |
| CVE-2014-2316 | — | — | 2.2% | Mar 9, 2014 | SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remot... |
| CVE-2014-2315 | — | — | 2.0% | Mar 9, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.8.7 for WordPress allow rem... |
| CVE-2014-2314 | — | — | 26.0% | Mar 9, 2014 | Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t... |
| CVE-2014-2313 | — | — | 2.1% | Mar 9, 2014 | Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to crea... |
| CVE-2014-1945 | — | — | 1.4% | Mar 9, 2014 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ... |
| CVE-2014-1944 | — | — | 3.3% | Mar 9, 2014 | Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web scr... |
| CVE-2014-1599 | — | — | 0.9% | Mar 9, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the SFR Box router with firmware NB6-MAIN-R3.3.4 allow remote att... |
| CVE-2014-1959 | — | — | 3.4% | Mar 7, 2014 | lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CA... |
| CVE-2014-0092 | — | — | 30.0% | Mar 7, 2014 | lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verif... |
| CVE-2014-1907 | — | — | 10.8% | Mar 6, 2014 | Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor... |
| CVE-2014-1906 | — | — | 4.5% | Mar 6, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 ... |
| CVE-2014-1911 | — | — | 1.4% | Mar 6, 2014 | The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image da... |
| CVE-2014-0890 | — | — | 0.3% | Mar 6, 2014 | The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.col... |
| CVE-2014-0707 | — | — | 1.3% | Mar 6, 2014 | Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial ... |
| CVE-2014-0706 | — | — | 1.3% | Mar 6, 2014 | Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers t... |
| CVE-2014-0705 | — | — | 1.7% | Mar 6, 2014 | The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.1... |
| CVE-2014-0704 | — | — | 1.2% | Mar 6, 2014 | The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, an... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now