2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0835Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers ...
CVE-2014-1683The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248...
CVE-2014-0682Cisco WebEx Meetings Server allows remote authenticated users to bypass authorization checks and (1) join arbitrary meet...
CVE-2014-0681Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote a...
CVE-2014-0680Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity ...
CVE-2014-1692HIGH7.3The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protoco...
CVE-2014-0810Unspecified vulnerability in JustSystems Sanshiro 2007 before update 3, 2008 before update 5, 2009 before update 6, and ...
CVE-2014-0025Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-1690. Reason: This candidate is a reservation ...
CVE-2014-1681Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.102 have unknown impact and attack vectors, relat...
CVE-2014-1640axiom-test.sh in axiom 20100701-1.1 uses tempfile to create a safe temporary file but appends a suffix to the original f...
CVE-2014-1639syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a...
CVE-2014-1638(1) debian/postrm and (2) debian/localepurge.config in localepurge before 0.7.3.2 use tempfile to create a safe temporar...
CVE-2014-1624Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbi...
CVE-2014-1604The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof ...
CVE-2014-0647The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/...
CVE-2014-1664The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which a...
CVE-2014-1607Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject a...
CVE-2014-0794SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authentic...
CVE-2014-1666The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to th...
CVE-2014-1642The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, fr...
CVE-2014-0022The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of...
CVE-2014-1673Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via ...
CVE-2014-1672Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table...
CVE-2014-1671Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remot...
CVE-2014-1626XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, per...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now