2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-8487Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) ...
CVE-2014-7922The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests u...
CVE-2014-6184Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through...
CVE-2014-8115The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitr...
CVE-2014-8114The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary co...
CVE-2014-3682XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2Resour...
CVE-2014-0005PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0....
CVE-2014-5355MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a str...
CVE-2014-3578Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attack...
CVE-2014-9679Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers t...
CVE-2014-9468Multiple cross-site scripting (XSS) vulnerabilities in InstantASP InstantForum.NET 4.1.3, 4.1.2, 4.1.1, 4.0.0, 4.1.0, an...
CVE-2014-9465senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1....
CVE-2014-8690Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an...
CVE-2014-8165scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote ...
CVE-2014-1832Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) contro...
CVE-2014-1831Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1)...
CVE-2014-9423The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5...
CVE-2014-9422The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1...
CVE-2014-9421The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x t...
CVE-2014-6304The Form Controls CSS file in PNMsoft Sequence Kinetics before 7.7 allows remote attackers to obtain sensitive source-co...
CVE-2014-6303The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 do not properly detect recursion during enti...
CVE-2014-6302The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 allow remote attackers to read arbitrary fil...
CVE-2014-6301Multiple cross-site scripting (XSS) vulnerabilities in the tables-management module in PNMsoft Sequence Kinetics before ...
CVE-2014-5352The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in ...
CVE-2014-6147IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sens...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now