2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-2745Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers...
CVE-2014-2744plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compr...
CVE-2014-2743plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed ...
CVE-2014-2742Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote att...
CVE-2014-2741nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of comp...
CVE-2014-0920IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authentic...
CVE-2014-0908The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, an...
CVE-2014-2752SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote att...
CVE-2014-2751SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access v...
CVE-2014-2750Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2744, CVE-2014-2745. Reason: This candidate is...
CVE-2014-2749The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and...
CVE-2014-2748The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or ...
CVE-2014-2708Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to...
CVE-2014-2583Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1....
CVE-2014-1455SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, p...
CVE-2014-0331Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allo...
CVE-2014-2141The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initial...
CVE-2014-2129The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5),...
CVE-2014-2128The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40)...
CVE-2014-2127Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 be...
CVE-2014-2126Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 be...
CVE-2014-2544Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in ...
CVE-2014-0166The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does ...
CVE-2014-0165WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contr...
CVE-2014-1729Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allo...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now