2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9048 | — | — | 1.2% | Feb 4, 2015 | The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the... |
| CVE-2014-9047 | — | — | 1.1% | Feb 4, 2015 | Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x before 6.0.6 and 7.x before 7.0.3 allow remot... |
| CVE-2014-9046 | — | — | 1.2% | Feb 4, 2015 | The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remo... |
| CVE-2014-9045 | — | — | 1.9% | Feb 4, 2015 | The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass... |
| CVE-2014-9044 | — | — | 1.2% | Feb 4, 2015 | Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files... |
| CVE-2014-9043 | — | — | 1.9% | Feb 4, 2015 | The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before ... |
| CVE-2014-9042 | — | — | 1.1% | Feb 4, 2015 | Cross-site scripting (XSS) vulnerability in the import functionality in the bookmarks application in ownCloud before 5.0... |
| CVE-2014-9041 | — | — | 0.8% | Feb 4, 2015 | The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before... |
| CVE-2014-5341 | — | — | 1.1% | Feb 4, 2015 | The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login... |
| CVE-2014-9331 | — | — | 4.6% | Feb 4, 2015 | Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote ... |
| CVE-2014-7864 | — | — | 22.7% | Feb 4, 2015 | Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan... |
| CVE-2014-8021 | — | — | 1.8% | Feb 3, 2015 | Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco Ho... |
| CVE-2014-8013 | — | — | 0.3% | Feb 3, 2015 | The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device ... |
| CVE-2014-9633 | — | — | 8.1% | Feb 3, 2015 | The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha... |
| CVE-2014-9574 | — | — | 2.6% | Feb 3, 2015 | Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows remote attackers to include and execute a... |
| CVE-2014-9568 | — | — | 0.4% | Feb 3, 2015 | puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local u... |
| CVE-2014-9559 | — | — | 0.9% | Feb 3, 2015 | Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrar... |
| CVE-2014-9556 | — | — | 2.8% | Feb 3, 2015 | Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (... |
| CVE-2014-9328 | — | — | 3.2% | Feb 3, 2015 | ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "h... |
| CVE-2014-8779 | — | — | 1.4% | Feb 3, 2015 | Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-m... |
| CVE-2014-5360 | — | — | 1.0% | Feb 3, 2015 | Cross-site scripting (XSS) vulnerability in the admin interface in LANDESK Management Suite before 9.6 SP1 allows remote... |
| CVE-2014-8613 | — | — | 2.8% | Feb 2, 2015 | The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to... |
| CVE-2014-8612 | — | — | 0.9% | Feb 2, 2015 | Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be... |
| CVE-2014-0998 | — | — | 0.9% | Feb 2, 2015 | Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows... |
| CVE-2014-8918 | — | — | 0.5% | Feb 2, 2015 | IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL server... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now