2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9048The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the...
CVE-2014-9047Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x before 6.0.6 and 7.x before 7.0.3 allow remot...
CVE-2014-9046The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remo...
CVE-2014-9045The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass...
CVE-2014-9044Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files...
CVE-2014-9043The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before ...
CVE-2014-9042Cross-site scripting (XSS) vulnerability in the import functionality in the bookmarks application in ownCloud before 5.0...
CVE-2014-9041The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before...
CVE-2014-5341The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login...
CVE-2014-9331Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote ...
CVE-2014-7864Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan...
CVE-2014-8021Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco Ho...
CVE-2014-8013The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device ...
CVE-2014-9633The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha...
CVE-2014-9574Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows remote attackers to include and execute a...
CVE-2014-9568puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local u...
CVE-2014-9559Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrar...
CVE-2014-9556Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (...
CVE-2014-9328ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "h...
CVE-2014-8779Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-m...
CVE-2014-5360Cross-site scripting (XSS) vulnerability in the admin interface in LANDESK Management Suite before 9.6 SP1 allows remote...
CVE-2014-8613The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to...
CVE-2014-8612Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be...
CVE-2014-0998Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows...
CVE-2014-8918IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL server...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now