2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3656 | MEDIUM | 6.1 | 0.7% | Dec 10, 2019 | JBoss KeyCloak: XSS in login-status-iframe.html |
| CVE-2014-3591 | MEDIUM | 4.2 | 0.6% | Nov 29, 2019 | Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allo... |
| CVE-2014-3875 | MEDIUM | 6.1 | 1.7% | Nov 27, 2019 | The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to co... |
| CVE-2014-2214 | MEDIUM | 6.1 | 0.8% | Nov 22, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote... |
| CVE-2014-2213 | MEDIUM | 6.1 | 1.4% | Nov 22, 2019 | Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to red... |
| CVE-2014-1238 | MEDIUM | 6.1 | 0.6% | Nov 22, 2019 | Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier. |
| CVE-2014-5254 | MEDIUM | 4.7 | 0.3% | Nov 21, 2019 | xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr... |
| CVE-2014-1938 | MEDIUM | 5.5 | 0.4% | Nov 21, 2019 | python-rply before 0.7.4 insecurely creates temporary files. |
| CVE-2014-1935 | MEDIUM | 5.3 | 1.4% | Nov 21, 2019 | 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. |
| CVE-2014-0084 | MEDIUM | 5.5 | 0.3% | Nov 21, 2019 | Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se... |
| CVE-2014-0083 | MEDIUM | 5.5 | 0.3% | Nov 21, 2019 | The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords. |
| CVE-2014-5118 | MEDIUM | 5.5 | 0.4% | Nov 18, 2019 | Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability |
| CVE-2014-8167 | MEDIUM | 5.9 | 0.7% | Nov 13, 2019 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle at... |
| CVE-2014-3655 | MEDIUM | 4.3 | 0.5% | Nov 13, 2019 | JBoss KeyCloak is vulnerable to soft token deletion via CSRF |
| CVE-2014-3592 | MEDIUM | 6.1 | 0.7% | Nov 13, 2019 | OpenShift Origin: Improperly validated team names could allow stored XSS attacks |
| CVE-2014-3599 | MEDIUM | 6.5 | 1.2% | Nov 12, 2019 | HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy |
| CVE-2014-9014 | MEDIUM | 4.3 | 11.9% | Nov 6, 2019 | Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b... |
| CVE-2014-8181 | MEDIUM | 5.5 | 0.4% | Nov 6, 2019 | The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensi... |
| CVE-2014-3649 | MEDIUM | 6.1 | 0.7% | Nov 4, 2019 | JBoss AeroGear has reflected XSS via the password field |
| CVE-2014-10377 | MEDIUM | 6.1 | 0.9% | Aug 21, 2019 | The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. |
| CVE-2014-9563 | MEDIUM | 4.9 | 1.2% | Apr 12, 2018 | CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and Ope... |
| CVE-2014-2312 | MEDIUM | 5.5 | 0.4% | Mar 26, 2018 | The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on... |
| CVE-2014-4024 | MEDIUM | 5.9 | 1.6% | Mar 19, 2018 | SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 bef... |
| CVE-2014-4919 | MEDIUM | 5.4 | 0.8% | Jan 19, 2018 | OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before ... |
| CVE-2014-9482 | MEDIUM | 6.5 | 2.2% | Jan 16, 2018 | Use-after-free vulnerability in dwarfdump in libdwarf 20130126 through 20140805 might allow remote attackers to cause a ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now