2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-3598The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted i...
CVE-2014-6092IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 befor...
CVE-2014-6090Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorComm...
CVE-2014-8125XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files ...
CVE-2014-8111Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which al...
CVE-2014-3586The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and Wil...
CVE-2014-9718The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretatio...
CVE-2014-5370Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDra...
CVE-2014-5361Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote atta...
CVE-2014-9488The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed...
CVE-2014-8360Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include ...
CVE-2014-5032GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensit...
CVE-2014-9311Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo...
CVE-2014-9146Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s...
CVE-2014-9145Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via ...
CVE-2014-9714Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Mac...
CVE-2014-4315Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA who allocated this candidate did ...
CVE-2014-4314Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA who allocated this candidate did ...
CVE-2014-6221The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0...
CVE-2014-8390Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malforme...
CVE-2014-5405Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote...
CVE-2014-5403Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, whi...
CVE-2014-5400The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allow...
CVE-2014-9713The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated u...
CVE-2014-9708Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer de...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now