2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-3598——The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted i...
CVE-2014-6092——IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 befor...
CVE-2014-6090——Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorComm...
CVE-2014-8125——XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files ...
CVE-2014-8111——Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which al...
CVE-2014-3586——The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and Wil...
CVE-2014-9718——The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretatio...
CVE-2014-5370——Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDra...
CVE-2014-5361——Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote atta...
CVE-2014-9488——The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed...
CVE-2014-8360——Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include ...
CVE-2014-5032——GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensit...
CVE-2014-9311——Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo...
CVE-2014-9146——Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s...
CVE-2014-9145——Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via ...
CVE-2014-9714——Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Mac...
CVE-2014-4315——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA who allocated this candidate did ...
CVE-2014-4314——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA who allocated this candidate did ...
CVE-2014-6221——The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0...
CVE-2014-8390——Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malforme...
CVE-2014-5405——Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote...
CVE-2014-5403——Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, whi...
CVE-2014-5400——The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allow...
CVE-2014-9713——The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated u...
CVE-2014-9708——Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer de...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now