2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-8617——Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMai...
CVE-2014-9683——Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the ...
CVE-2014-9283——The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mecha...
CVE-2014-7896——Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, a...
CVE-2014-9644——The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system c...
CVE-2014-8160——net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during ...
CVE-2014-8921——The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Not...
CVE-2014-9682——The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell ...
CVE-2014-9676——The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory loca...
CVE-2014-2188——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-0607. Reason: This candidate is a duplicate of...
CVE-2014-9685——Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remo...
CVE-2014-9282——Directory traversal vulnerability in the Speed Root Explorer application before 3.2 for Android and the Speed Explorer a...
CVE-2014-6115——IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a cra...
CVE-2014-4818——dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows l...
CVE-2014-9684——OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which al...
CVE-2014-9402——The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Se...
CVE-2014-8487——Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) ...
CVE-2014-7922——The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests u...
CVE-2014-6184——Stack-based buffer overflow in dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4 through 5.4.3.6, 5.5 through...
CVE-2014-8115——The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitr...
CVE-2014-8114——The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary co...
CVE-2014-3682——XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2Resour...
CVE-2014-0005——PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0....
CVE-2014-5355——MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a str...
CVE-2014-3578——Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attack...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now