2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9488The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed...
CVE-2014-8360Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include ...
CVE-2014-5032GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensit...
CVE-2014-9311Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo...
CVE-2014-9146Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s...
CVE-2014-9145Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via ...
CVE-2014-9714Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Mac...
CVE-2014-4315Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA who allocated this candidate did ...
CVE-2014-4314Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA who allocated this candidate did ...
CVE-2014-6221The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0...
CVE-2014-8390Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malforme...
CVE-2014-5405Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote...
CVE-2014-5403Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, whi...
CVE-2014-5400The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allow...
CVE-2014-9713The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated u...
CVE-2014-9708Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer de...
CVE-2014-9707EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remot...
CVE-2014-9706The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code...
CVE-2014-9462The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands vi...
CVE-2014-2830Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remot...
CVE-2014-2027eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary fil...
CVE-2014-7876Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Man...
CVE-2014-9209Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platfor...
CVE-2014-9709The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allow...
CVE-2014-9705Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5....

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now