2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6448 | HIGH | 7.8 | 0.3% | Jan 15, 2020 | Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restr... |
| CVE-2014-7844 | HIGH | 7.8 | 1.6% | Jan 14, 2020 | BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address. |
| CVE-2014-2271 | HIGH | 8.1 | 1.5% | Jan 14, 2020 | cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R0... |
| CVE-2014-5238 | HIGH | 7.8 | 1.9% | Jan 14, 2020 | XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 all... |
| CVE-2014-5138 | HIGH | 7.5 | 1.6% | Jan 14, 2020 | Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instan... |
| CVE-2014-4610 | HIGH | 8.8 | 4.5% | Jan 14, 2020 | Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before ... |
| CVE-2014-4609 | HIGH | 8.8 | 5.7% | Jan 14, 2020 | Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.... |
| CVE-2014-6059 | HIGH | 7.2 | 3.3% | Jan 13, 2020 | WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability |
| CVE-2014-6039 | HIGH | 7.5 | 68.8% | Jan 13, 2020 | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio... |
| CVE-2014-6038 | HIGH | 7.5 | 72.8% | Jan 13, 2020 | Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili... |
| CVE-2014-5380 | HIGH | 7.5 | 4.3% | Jan 13, 2020 | Grand MA 300 allows retrieval of the access PIN from sniffed data. |
| CVE-2014-5092 | HIGH | 8.8 | 7.1% | Jan 10, 2020 | Status2k allows Remote Command Execution in admin/options/editpl.php. |
| CVE-2014-5013 | HIGH | 8.8 | 4.6% | Jan 10, 2020 | DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383. |
| CVE-2014-3447 | HIGH | 7.5 | 1.8% | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability |
| CVE-2014-3211 | HIGH | 7.5 | 1.1% | Jan 9, 2020 | Publify before 8.0.1 is vulnerable to a Denial of Service attack |
| CVE-2014-2686 | HIGH | 7.5 | 1.2% | Jan 9, 2020 | Ansible prior to 1.5.4 mishandles the evaluation of some strings. |
| CVE-2014-5287 | HIGH | 8.8 | 8.1% | Jan 8, 2020 | A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input i... |
| CVE-2014-5140 | HIGH | 8.8 | 2.7% | Jan 3, 2020 | The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly ha... |
| CVE-2014-8182 | HIGH | 7.5 | 3.1% | Jan 2, 2020 | An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was con... |
| CVE-2014-3136 | HIGH | 8.8 | 2.9% | Dec 27, 2019 | Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote a... |
| CVE-2014-8179 | HIGH | 7.5 | 2.7% | Dec 17, 2019 | Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest obj... |
| CVE-2014-3701 | HIGH | 8.1 | 1.5% | Dec 15, 2019 | eDeploy has tmp file race condition flaws |
| CVE-2014-3643 | HIGH | 7.5 | 2.1% | Dec 15, 2019 | jersey: XXE via parameter entities not disabled by the jersey SAX parser |
| CVE-2014-3495 | HIGH | 7.5 | 0.9% | Dec 13, 2019 | duplicity 0.6.24 has improper verification of SSL certificates |
| CVE-2014-1867 | HIGH | 7.8 | 0.4% | Dec 13, 2019 | suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now