2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0593 | HIGH | 7.8 | 1.9% | Jun 8, 2018 | The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). I... |
| CVE-2014-10066 | HIGH | 7.5 | 1.6% | May 31, 2018 | Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacke... |
| CVE-2014-10068 | HIGH | 7.5 | 1.9% | May 29, 2018 | The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, ev... |
| CVE-2014-10073 | HIGH | 7.5 | 2.3% | Apr 20, 2018 | The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a ch... |
| CVE-2014-8422 | HIGH | 8.1 | 1.6% | Apr 12, 2018 | The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices ... |
| CVE-2014-8421 | HIGH | 7.5 | 1.8% | Apr 12, 2018 | Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gai... |
| CVE-2014-6309 | HIGH | 7.5 | 1.5% | Apr 12, 2018 | The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edit... |
| CVE-2014-5280 | HIGH | 8.8 | 0.7% | Feb 6, 2018 | boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker d... |
| CVE-2014-8166 | HIGH | 8.8 | 3.7% | Jan 12, 2018 | The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might ... |
| CVE-2014-5070 | HIGH | 8.8 | 1.7% | Jan 11, 2018 | Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenti... |
| CVE-2014-5068 | HIGH | 7.5 | 2.7% | Jan 11, 2018 | Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read ar... |
| CVE-2014-3526 | HIGH | 7.5 | 2.3% | Oct 30, 2017 | Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive... |
| CVE-2014-2277 | HIGH | 7.1 | 0.4% | Oct 17, 2017 | The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive informati... |
| CVE-2014-7808 | HIGH | 7.5 | 1.1% | Sep 15, 2017 | Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptog... |
| CVE-2014-9831 | HIGH | 8.8 | 1.9% | Aug 7, 2017 | coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file. |
| CVE-2014-9830 | HIGH | 8.8 | 1.9% | Aug 7, 2017 | coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file. |
| CVE-2014-9828 | HIGH | 8.8 | 2.0% | Aug 7, 2017 | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file. |
| CVE-2014-9827 | HIGH | 8.8 | 1.9% | Aug 7, 2017 | coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file. |
| CVE-2014-3462 | HIGH | 7.5 | 3.1% | Aug 7, 2017 | The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "... |
| CVE-2014-9260 | HIGH | 8.8 | 11.1% | Aug 7, 2017 | The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users ... |
| CVE-2014-9940 | HIGH | 7 | 1.6% | May 2, 2017 | The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to g... |
| CVE-2014-9114 | HIGH | 7.8 | 0.6% | Mar 31, 2017 | Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code. |
| CVE-2014-9825 | HIGH | 7.8 | 1.4% | Mar 30, 2017 | Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a d... |
| CVE-2014-9824 | HIGH | 7.8 | 1.6% | Mar 30, 2017 | Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a d... |
| CVE-2014-9823 | HIGH | 7.8 | 1.6% | Mar 30, 2017 | Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted palm file, a ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now