2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-125005 | MEDIUM | 5.5 | 0.6% | Jun 18, 2022 | A vulnerability, which was classified as problematic, was found in FFmpeg 2.0. This affects the function decode_vol_head... |
| CVE-2014-125004 | MEDIUM | 5.5 | 0.6% | Jun 18, 2022 | A vulnerability has been found in FFmpeg 2.0 and classified as problematic. This vulnerability affects the function deco... |
| CVE-2014-125003 | MEDIUM | 5.5 | 0.6% | Jun 18, 2022 | A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function get_siz of the fi... |
| CVE-2014-125002 | MEDIUM | 5.5 | 0.6% | Jun 18, 2022 | A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function dnxhd_init_rc o... |
| CVE-2014-125001 | HIGH | 8.8 | 3.4% | May 24, 2022 | A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api o... |
| CVE-2014-8597 | MEDIUM | 6.1 | 0.8% | Feb 17, 2022 | A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary w... |
| CVE-2014-9320 | CRITICAL | 9.8 | 4.2% | Aug 9, 2021 | SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and conse... |
| CVE-2014-7856 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2014-7855 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2014-7820 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2014-10402 | MEDIUM | 6.1 | 0.5% | Sep 16, 2020 | An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other th... |
| CVE-2014-10401 | MEDIUM | 6.1 | 0.4% | Sep 11, 2020 | An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other tha... |
| CVE-2014-1420 | LOW | 3.3 | 0.5% | Sep 11, 2020 | On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose pote... |
| CVE-2014-1422 | MEDIUM | 5 | 0.4% | Jul 22, 2020 | In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the a... |
| CVE-2014-9702 | HIGH | 7.5 | 1.3% | Jun 1, 2020 | system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers ... |
| CVE-2014-8945 | CRITICAL | 9.8 | 2.4% | Jun 1, 2020 | admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields. |
| CVE-2014-8944 | MEDIUM | 5.4 | 0.5% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config insta... |
| CVE-2014-8943 | HIGH | 8.8 | 1.0% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter. |
| CVE-2014-8942 | HIGH | 8.8 | 0.5% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows CSRF. |
| CVE-2014-8941 | CRITICAL | 9.8 | 1.1% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= U... |
| CVE-2014-8940 | MEDIUM | 5.3 | 1.1% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by v... |
| CVE-2014-8939 | MEDIUM | 5.3 | 1.4% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/pl... |
| CVE-2014-8938 | HIGH | 7.8 | 0.3% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username... |
| CVE-2014-8937 | HIGH | 7.5 | 1.1% | Jun 1, 2020 | Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a gr... |
| CVE-2014-7175 | CRITICAL | 9.8 | 1.3% | Jun 1, 2020 | FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php. |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now