2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6276 | — | — | 1.5% | Apr 13, 2016 | schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might a... |
| CVE-2014-9759 | — | — | 1.9% | Apr 11, 2016 | Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 al... |
| CVE-2014-9769 | — | — | 2.4% | Mar 28, 2016 | pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote a... |
| CVE-2014-9768 | — | — | 1.9% | Mar 18, 2016 | IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM comma... |
| CVE-2014-0292 | — | — | — | Feb 23, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-9757 | — | — | 2.3% | Feb 8, 2016 | The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote con... |
| CVE-2014-7151 | — | — | 1.2% | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attack... |
| CVE-2014-6444 | — | — | 1.2% | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote ... |
| CVE-2014-8886 | — | — | 6.1% | Jan 8, 2016 | AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which... |
| CVE-2014-5040 | — | — | 0.6% | Jan 5, 2016 | HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to... |
| CVE-2014-4876 | — | — | 1.7% | Dec 31, 2015 | Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote atta... |
| CVE-2014-3260 | — | — | 1.2% | Dec 31, 2015 | Pacom 1000 CCU and RTU GMS devices allow remote attackers to spoof the controller-to-base data stream by leveraging impr... |
| CVE-2014-3665 | — | — | 2.5% | Nov 25, 2015 | Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which m... |
| CVE-2014-9756 | — | — | 2.9% | Nov 19, 2015 | The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error a... |
| CVE-2014-9752 | — | — | 2.1% | Nov 16, 2015 | Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows r... |
| CVE-2014-8873 | — | — | 4.5% | Nov 9, 2015 | A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /... |
| CVE-2014-9749 | — | — | 11.4% | Nov 6, 2015 | Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated use... |
| CVE-2014-8912 | — | — | 2.1% | Oct 28, 2015 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8... |
| CVE-2014-8242 | — | — | 2.9% | Oct 26, 2015 | librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modif... |
| CVE-2014-6451 | — | — | 1.9% | Oct 16, 2015 | J-Web in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of se... |
| CVE-2014-6450 | — | — | 1.9% | Oct 16, 2015 | Juniper Junos OS before 11.4R12-S4, 12.1X44 before 12.1X44-D41, 12.1X46 before 12.1X46-D26, 12.1X47 before 12.1X47-D11/D... |
| CVE-2014-6449 | — | — | 1.7% | Oct 16, 2015 | Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X4... |
| CVE-2014-9751 | — | — | 4.5% | Oct 6, 2015 | The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly deter... |
| CVE-2014-9750 | — | — | 6.2% | Oct 6, 2015 | ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtai... |
| CVE-2014-9298 | — | — | — | Oct 6, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9750, CVE-2014-9751. Reason: this ID was inten... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now