2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9048——The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the...
CVE-2014-9047——Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x before 6.0.6 and 7.x before 7.0.3 allow remot...
CVE-2014-9046——The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remo...
CVE-2014-9045——The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass...
CVE-2014-9044——Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files...
CVE-2014-9043——The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before ...
CVE-2014-9042——Cross-site scripting (XSS) vulnerability in the import functionality in the bookmarks application in ownCloud before 5.0...
CVE-2014-9041——The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before...
CVE-2014-5341——The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login...
CVE-2014-9331——Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote ...
CVE-2014-7864——Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan...
CVE-2014-8021——Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco Ho...
CVE-2014-8013——The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device ...
CVE-2014-9633——The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha...
CVE-2014-9574——Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows remote attackers to include and execute a...
CVE-2014-9568——puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local u...
CVE-2014-9559——Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrar...
CVE-2014-9556——Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (...
CVE-2014-9328——ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "h...
CVE-2014-8779——Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-m...
CVE-2014-5360——Cross-site scripting (XSS) vulnerability in the admin interface in LANDESK Management Suite before 9.6 SP1 allows remote...
CVE-2014-8613——The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to...
CVE-2014-8612——Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be...
CVE-2014-0998——Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows...
CVE-2014-8918——IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL server...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now