2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2014-3656MEDIUM6.1JBoss KeyCloak: XSS in login-status-iframe.html
CVE-2014-3591MEDIUM4.2Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allo...
CVE-2014-3875MEDIUM6.1The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to co...
CVE-2014-2214MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote...
CVE-2014-2213MEDIUM6.1Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to red...
CVE-2014-1238MEDIUM6.1Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier.
CVE-2014-5254MEDIUM4.7xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr...
CVE-2014-1938MEDIUM5.5python-rply before 0.7.4 insecurely creates temporary files.
CVE-2014-1935MEDIUM5.39base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
CVE-2014-0084MEDIUM5.5Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se...
CVE-2014-0083MEDIUM5.5The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
CVE-2014-5118MEDIUM5.5Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
CVE-2014-8167MEDIUM5.9vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle at...
CVE-2014-3655MEDIUM4.3JBoss KeyCloak is vulnerable to soft token deletion via CSRF
CVE-2014-3592MEDIUM6.1OpenShift Origin: Improperly validated team names could allow stored XSS attacks
CVE-2014-3599MEDIUM6.5HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
CVE-2014-9014MEDIUM4.3Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b...
CVE-2014-8181MEDIUM5.5The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensi...
CVE-2014-3649MEDIUM6.1JBoss AeroGear has reflected XSS via the password field
CVE-2014-10377MEDIUM6.1The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
CVE-2014-9563MEDIUM4.9CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and Ope...
CVE-2014-2312MEDIUM5.5The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on...
CVE-2014-4024MEDIUM5.9SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 bef...
CVE-2014-4919MEDIUM5.4OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before ...
CVE-2014-9482MEDIUM6.5Use-after-free vulnerability in dwarfdump in libdwarf 20130126 through 20140805 might allow remote attackers to cause a ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now