2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9653readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x be...
CVE-2014-9652The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x ...
CVE-2014-9205Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMO...
CVE-2014-5428Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used ...
CVE-2014-5427Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Se...
CVE-2014-9712Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to rea...
CVE-2014-8121DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earli...
CVE-2014-3619The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinit...
CVE-2014-9711Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 ...
CVE-2014-8925Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0....
CVE-2014-8923The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active ...
CVE-2014-6134IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, r...
CVE-2014-9261The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which ...
CVE-2014-8169automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environmen...
CVE-2014-6131IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi...
CVE-2014-6129IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFi...
CVE-2014-9687eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obt...
CVE-2014-8173The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUM...
CVE-2014-8172The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inap...
CVE-2014-8159The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL)...
CVE-2014-7822The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restrictio...
CVE-2014-9207Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows l...
CVE-2014-9206Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control V...
CVE-2014-7885Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact an...
CVE-2014-7884Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated att...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now