2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2014-8516CRITICAL9.8Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary co...
CVE-2014-8337CRITICAL9.8Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier ...
CVE-2014-0011CRITICAL9.8Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, wh...
CVE-2014-0048CRITICAL9.8An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed...
CVE-2014-5289CRITICAL9.8Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request...
CVE-2014-8650CRITICAL9.8python-requests-Kerberos through 0.5 does not handle mutual authentication
CVE-2014-3699CRITICAL9.8eDeploy has RCE via cPickle deserialization of untrusted data
CVE-2014-0175CRITICAL9.8mcollective has a default password set at install
CVE-2014-7257CRITICAL9.8SQL injection vulnerability in DBD::PgPP 0.05 and earlier
CVE-2014-6311CRITICAL9.8generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attacker...
CVE-2014-6310CRITICAL9.8Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' funct...
CVE-2014-3585CRITICAL9.8redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
CVE-2014-3700CRITICAL9.8eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
CVE-2014-3180CRITICAL9.1In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible ...
CVE-2014-2073CRITICAL9.8Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a...
CVE-2014-3539CRITICAL9.8base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveragi...
CVE-2014-5071CRITICAL9.8SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execut...
CVE-2014-9515CRITICAL9.8Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbi...
CVE-2014-1203CRITICAL9.8The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary comman...
CVE-2014-3931CRITICAL9.8fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory wr...
CVE-2014-9852CRITICAL9.8distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have ...
CVE-2014-5415CRITICAL9.1Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow r...
CVE-2014-5414CRITICAL9.1Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restri...
CVE-2014-9410CRITICAL9.8The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel ...
CVE-2014-8361CRITICAL9.8The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now