2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2014-6448HIGH7.8Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restr...
CVE-2014-7844HIGH7.8BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
CVE-2014-2271HIGH8.1cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R0...
CVE-2014-5238HIGH7.8XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 all...
CVE-2014-5138HIGH7.5Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instan...
CVE-2014-4610HIGH8.8Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before ...
CVE-2014-4609HIGH8.8Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10....
CVE-2014-6059HIGH7.2WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
CVE-2014-6039HIGH7.5ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio...
CVE-2014-6038HIGH7.5Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili...
CVE-2014-5380HIGH7.5Grand MA 300 allows retrieval of the access PIN from sniffed data.
CVE-2014-5092HIGH8.8Status2k allows Remote Command Execution in admin/options/editpl.php.
CVE-2014-5013HIGH8.8DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
CVE-2014-3447HIGH7.5BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability
CVE-2014-3211HIGH7.5Publify before 8.0.1 is vulnerable to a Denial of Service attack
CVE-2014-2686HIGH7.5Ansible prior to 1.5.4 mishandles the evaluation of some strings.
CVE-2014-5287HIGH8.8A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input i...
CVE-2014-5140HIGH8.8The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly ha...
CVE-2014-8182HIGH7.5An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was con...
CVE-2014-3136HIGH8.8Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote a...
CVE-2014-8179HIGH7.5Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest obj...
CVE-2014-3701HIGH8.1eDeploy has tmp file race condition flaws
CVE-2014-3643HIGH7.5jersey: XXE via parameter entities not disabled by the jersey SAX parser
CVE-2014-3495HIGH7.5duplicity 0.6.24 has improper verification of SSL certificates
CVE-2014-1867HIGH7.8suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now