2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2014-0593HIGH7.8The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). I...
CVE-2014-10066HIGH7.5Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacke...
CVE-2014-10068HIGH7.5The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, ev...
CVE-2014-10073HIGH7.5The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a ch...
CVE-2014-8422HIGH8.1The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices ...
CVE-2014-8421HIGH7.5Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gai...
CVE-2014-6309HIGH7.5The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edit...
CVE-2014-5280HIGH8.8boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker d...
CVE-2014-8166HIGH8.8The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might ...
CVE-2014-5070HIGH8.8Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenti...
CVE-2014-5068HIGH7.5Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read ar...
CVE-2014-3526HIGH7.5Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive...
CVE-2014-2277HIGH7.1The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive informati...
CVE-2014-7808HIGH7.5Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptog...
CVE-2014-9831HIGH8.8coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.
CVE-2014-9830HIGH8.8coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.
CVE-2014-9828HIGH8.8coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.
CVE-2014-9827HIGH8.8coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.
CVE-2014-3462HIGH7.5The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "...
CVE-2014-9260HIGH8.8The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users ...
CVE-2014-9940HIGH7The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to g...
CVE-2014-9114HIGH7.8Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
CVE-2014-9825HIGH7.8Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a d...
CVE-2014-9824HIGH7.8Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a d...
CVE-2014-9823HIGH7.8Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted palm file, a ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now