2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2014-0212HIGH7.5qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descrip...
CVE-2014-0197HIGH8.8CFME: CSRF protection vulnerability via permissive check of the referrer header
CVE-2014-0163HIGH8.8Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
CVE-2014-0242HIGH7.5mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info...
CVE-2014-9356HIGH8.6Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a con...
CVE-2014-5255HIGH7xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr...
CVE-2014-2904HIGH7.5wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
CVE-2014-2902HIGH7.5wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
CVE-2014-2901HIGH7.5wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
CVE-2014-8356HIGH8.8The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a...
CVE-2014-1937HIGH7.5Gamera before 3.4.1 insecurely creates temporary files.
CVE-2014-1936HIGH7.5rc before 1.7.1-5 insecurely creates temporary files.
CVE-2014-5439HIGH7.8Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file t...
CVE-2014-0023HIGH7.8OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
CVE-2014-0021HIGH7.5Chrony before 1.29.1 has traffic amplification in cmdmon protocol
CVE-2014-1214HIGH8.8views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attac...
CVE-2014-7143HIGH7.5Python Twisted 14.0 trustRoot is not respected in HTTP client
CVE-2014-9013HIGH8.8The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth...
CVE-2014-2304HIGH7.5A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attac...
CVE-2014-10397HIGH7.5The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts...
CVE-2014-10396HIGH7.5The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl...
CVE-2014-8184HIGH7.8A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable...
CVE-2014-8183HIGH7.4It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on cert...
CVE-2014-1426HIGH8.6A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any...
CVE-2014-0594HIGH8.8In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, a...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now