2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9707 | — | — | 28.4% | Mar 31, 2015 | EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remot... |
| CVE-2014-9706 | — | — | 5.0% | Mar 31, 2015 | The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code... |
| CVE-2014-9462 | — | — | 4.2% | Mar 31, 2015 | The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands vi... |
| CVE-2014-2830 | — | — | 5.2% | Mar 31, 2015 | Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remot... |
| CVE-2014-2027 | — | — | 4.0% | Mar 31, 2015 | eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary fil... |
| CVE-2014-7876 | — | — | 12.9% | Mar 31, 2015 | Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Man... |
| CVE-2014-9209 | — | — | 0.7% | Mar 31, 2015 | Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platfor... |
| CVE-2014-9709 | — | — | 15.1% | Mar 30, 2015 | The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allow... |
| CVE-2014-9705 | — | — | 18.8% | Mar 30, 2015 | Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.... |
| CVE-2014-9653 | — | — | 4.7% | Mar 30, 2015 | readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x be... |
| CVE-2014-9652 | — | — | 5.5% | Mar 30, 2015 | The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x ... |
| CVE-2014-9205 | — | — | 4.8% | Mar 29, 2015 | Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMO... |
| CVE-2014-5428 | — | — | 3.9% | Mar 29, 2015 | Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used ... |
| CVE-2014-5427 | — | — | 1.4% | Mar 29, 2015 | Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Se... |
| CVE-2014-9712 | — | — | 0.9% | Mar 27, 2015 | Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to rea... |
| CVE-2014-8121 | — | — | 6.4% | Mar 27, 2015 | DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earli... |
| CVE-2014-3619 | — | — | 2.7% | Mar 27, 2015 | The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinit... |
| CVE-2014-9711 | — | — | 2.5% | Mar 25, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 ... |
| CVE-2014-8925 | — | — | 0.9% | Mar 25, 2015 | Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.... |
| CVE-2014-8923 | — | — | 0.4% | Mar 25, 2015 | The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active ... |
| CVE-2014-6134 | — | — | 0.3% | Mar 25, 2015 | IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, r... |
| CVE-2014-9261 | — | — | 9.1% | Mar 23, 2015 | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which ... |
| CVE-2014-8169 | — | — | 0.3% | Mar 18, 2015 | automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environmen... |
| CVE-2014-6131 | — | — | 1.3% | Mar 18, 2015 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi... |
| CVE-2014-6129 | — | — | 1.4% | Mar 18, 2015 | IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now