2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0212 | HIGH | 7.5 | 3.5% | Dec 13, 2019 | qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descrip... |
| CVE-2014-0197 | HIGH | 8.8 | 0.7% | Dec 13, 2019 | CFME: CSRF protection vulnerability via permissive check of the referrer header |
| CVE-2014-0163 | HIGH | 8.8 | 2.0% | Dec 11, 2019 | Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. |
| CVE-2014-0242 | HIGH | 7.5 | 8.5% | Dec 9, 2019 | mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info... |
| CVE-2014-9356 | HIGH | 8.6 | 4.9% | Dec 2, 2019 | Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a con... |
| CVE-2014-5255 | HIGH | 7 | 0.4% | Nov 21, 2019 | xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr... |
| CVE-2014-2904 | HIGH | 7.5 | 0.9% | Nov 21, 2019 | wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication. |
| CVE-2014-2902 | HIGH | 7.5 | 0.8% | Nov 21, 2019 | wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates. |
| CVE-2014-2901 | HIGH | 7.5 | 0.6% | Nov 21, 2019 | wolfssl before 3.2.0 does not properly issue certificates for a server's hostname. |
| CVE-2014-8356 | HIGH | 8.8 | 5.6% | Nov 21, 2019 | The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a... |
| CVE-2014-1937 | HIGH | 7.5 | 1.3% | Nov 21, 2019 | Gamera before 3.4.1 insecurely creates temporary files. |
| CVE-2014-1936 | HIGH | 7.5 | 1.3% | Nov 21, 2019 | rc before 1.7.1-5 insecurely creates temporary files. |
| CVE-2014-5439 | HIGH | 7.8 | 2.5% | Nov 19, 2019 | Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file t... |
| CVE-2014-0023 | HIGH | 7.8 | 0.4% | Nov 15, 2019 | OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution |
| CVE-2014-0021 | HIGH | 7.5 | 3.8% | Nov 15, 2019 | Chrony before 1.29.1 has traffic amplification in cmdmon protocol |
| CVE-2014-1214 | HIGH | 8.8 | 4.3% | Nov 13, 2019 | views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attac... |
| CVE-2014-7143 | HIGH | 7.5 | 2.6% | Nov 12, 2019 | Python Twisted 14.0 trustRoot is not respected in HTTP client |
| CVE-2014-9013 | HIGH | 8.8 | 47.9% | Nov 6, 2019 | The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth... |
| CVE-2014-2304 | HIGH | 7.5 | 1.1% | Oct 23, 2019 | A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attac... |
| CVE-2014-10397 | HIGH | 7.5 | 3.2% | Sep 20, 2019 | The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts... |
| CVE-2014-10396 | HIGH | 7.5 | 3.2% | Sep 20, 2019 | The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl... |
| CVE-2014-8184 | HIGH | 7.8 | 1.5% | Aug 2, 2019 | A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable... |
| CVE-2014-8183 | HIGH | 7.4 | 0.7% | Aug 1, 2019 | It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on cert... |
| CVE-2014-1426 | HIGH | 8.6 | 1.4% | Apr 22, 2019 | A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any... |
| CVE-2014-0594 | HIGH | 8.8 | 0.8% | Jun 8, 2018 | In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, a... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now