2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9763imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) vi...
CVE-2014-9762imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a ...
CVE-2014-9742The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, w...
CVE-2014-9717fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT...
CVE-2014-8486Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8496. Reason: This candidate is a duplicate of...
CVE-2014-9770tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and ...
CVE-2014-9765Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to ...
CVE-2014-9761Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent atta...
CVE-2014-9655The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows r...
CVE-2014-9766Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to c...
CVE-2014-6276schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might a...
CVE-2014-9759Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 al...
CVE-2014-9769pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote a...
CVE-2014-9768IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM comma...
CVE-2014-0292Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2014-9757The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote con...
CVE-2014-7151Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attack...
CVE-2014-6444Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote ...
CVE-2014-8886AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which...
CVE-2014-5040HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to...
CVE-2014-4876Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote atta...
CVE-2014-3260Pacom 1000 CCU and RTU GMS devices allow remote attackers to spoof the controller-to-base data stream by leveraging impr...
CVE-2014-3665Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which m...
CVE-2014-9756The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error a...
CVE-2014-9752Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows r...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now