2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-6276schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might a...
CVE-2014-9759Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 al...
CVE-2014-9769pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote a...
CVE-2014-9768IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM comma...
CVE-2014-0292Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2014-9757The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote con...
CVE-2014-7151Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attack...
CVE-2014-6444Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote ...
CVE-2014-8886AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which...
CVE-2014-5040HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to...
CVE-2014-4876Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote atta...
CVE-2014-3260Pacom 1000 CCU and RTU GMS devices allow remote attackers to spoof the controller-to-base data stream by leveraging impr...
CVE-2014-3665Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which m...
CVE-2014-9756The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error a...
CVE-2014-9752Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows r...
CVE-2014-8873A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /...
CVE-2014-9749Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated use...
CVE-2014-8912IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8...
CVE-2014-8242librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modif...
CVE-2014-6451J-Web in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of se...
CVE-2014-6450Juniper Junos OS before 11.4R12-S4, 12.1X44 before 12.1X44-D41, 12.1X46 before 12.1X46-D26, 12.1X47 before 12.1X47-D11/D...
CVE-2014-6449Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X4...
CVE-2014-9751The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly deter...
CVE-2014-9750ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtai...
CVE-2014-9298Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9750, CVE-2014-9751. Reason: this ID was inten...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now