2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9707EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remot...
CVE-2014-9706The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code...
CVE-2014-9462The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands vi...
CVE-2014-2830Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remot...
CVE-2014-2027eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary fil...
CVE-2014-7876Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Man...
CVE-2014-9209Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platfor...
CVE-2014-9709The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allow...
CVE-2014-9705Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5....
CVE-2014-9653readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x be...
CVE-2014-9652The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x ...
CVE-2014-9205Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMO...
CVE-2014-5428Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used ...
CVE-2014-5427Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Se...
CVE-2014-9712Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to rea...
CVE-2014-8121DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earli...
CVE-2014-3619The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinit...
CVE-2014-9711Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 ...
CVE-2014-8925Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0....
CVE-2014-8923The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active ...
CVE-2014-6134IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, r...
CVE-2014-9261The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which ...
CVE-2014-8169automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environmen...
CVE-2014-6131IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi...
CVE-2014-6129IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now