2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-125005MEDIUM5.5A vulnerability, which was classified as problematic, was found in FFmpeg 2.0. This affects the function decode_vol_head...
CVE-2014-125004MEDIUM5.5A vulnerability has been found in FFmpeg 2.0 and classified as problematic. This vulnerability affects the function deco...
CVE-2014-125003MEDIUM5.5A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function get_siz of the fi...
CVE-2014-125002MEDIUM5.5A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function dnxhd_init_rc o...
CVE-2014-125001HIGH8.8A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api o...
CVE-2014-8597MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary w...
CVE-2014-9320CRITICAL9.8SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and conse...
CVE-2014-7856Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2014-7855Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2014-7820Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2014-10402MEDIUM6.1An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other th...
CVE-2014-10401MEDIUM6.1An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other tha...
CVE-2014-1420LOW3.3On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose pote...
CVE-2014-1422MEDIUM5In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the a...
CVE-2014-9702HIGH7.5system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers ...
CVE-2014-8945CRITICAL9.8admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
CVE-2014-8944MEDIUM5.4Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config insta...
CVE-2014-8943HIGH8.8Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
CVE-2014-8942HIGH8.8Lexiglot through 2014-11-20 allows CSRF.
CVE-2014-8941CRITICAL9.8Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= U...
CVE-2014-8940MEDIUM5.3Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by v...
CVE-2014-8939MEDIUM5.3Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/pl...
CVE-2014-8938HIGH7.8Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username...
CVE-2014-8937HIGH7.5Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a gr...
CVE-2014-7175CRITICAL9.8FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now