2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-6616Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS Single Channel (FG-100-PB) with firmware FG-x00-PB_V...
CVE-2014-3148Cross-site scripting (XSS) vulnerability in libahttp/err.c in OkCupid OKWS (OK Web Server) allows remote attackers to in...
CVE-2014-2570Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP Font Lib before 0.3.1 allows remote attackers to ...
CVE-2014-2332Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a requ...
CVE-2014-2331Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted ...
CVE-2014-2330Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote ...
CVE-2014-2329Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote au...
CVE-2014-9731The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing ...
CVE-2014-9730The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are u...
CVE-2014-9729The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.18.2 does not ensure a certain data-structure...
CVE-2014-9728The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows loca...
CVE-2014-9651Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecifi...
CVE-2014-9744Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a lar...
CVE-2014-8987Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_rep...
CVE-2014-8628Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memor...
CVE-2014-6272Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2....
CVE-2014-3612The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x be...
CVE-2014-1972Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an obje...
CVE-2014-9743Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in Vide...
CVE-2014-8155GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-mid...
CVE-2014-3576The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote att...
CVE-2014-9736GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key ...
CVE-2014-7234Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7233. Reason: This issue was MERGED into CVE-201...
CVE-2014-7233GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2...
CVE-2014-7232GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser u...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now