2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-8487——Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) ...
CVE-2014-7922——The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests u...
CVE-2014-6184——Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through...
CVE-2014-8115——The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitr...
CVE-2014-8114——The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary co...
CVE-2014-3682——XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2Resour...
CVE-2014-0005——PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0....
CVE-2014-5355——MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a str...
CVE-2014-3578——Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attack...
CVE-2014-9679——Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers t...
CVE-2014-9468——Multiple cross-site scripting (XSS) vulnerabilities in InstantASP InstantForum.NET 4.1.3, 4.1.2, 4.1.1, 4.0.0, 4.1.0, an...
CVE-2014-9465——senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1....
CVE-2014-8690——Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an...
CVE-2014-8165——scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote ...
CVE-2014-1832——Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) contro...
CVE-2014-1831——Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1)...
CVE-2014-9423——The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5...
CVE-2014-9422——The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1...
CVE-2014-9421——The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x t...
CVE-2014-6304——The Form Controls CSS file in PNMsoft Sequence Kinetics before 7.7 allows remote attackers to obtain sensitive source-co...
CVE-2014-6303——The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 do not properly detect recursion during enti...
CVE-2014-6302——The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 allow remote attackers to read arbitrary fil...
CVE-2014-6301——Multiple cross-site scripting (XSS) vulnerabilities in the tables-management module in PNMsoft Sequence Kinetics before ...
CVE-2014-5352——The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in ...
CVE-2014-6147——IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sens...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now