2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9679 | — | — | 4.6% | Feb 19, 2015 | Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers t... |
| CVE-2014-9468 | — | — | 1.8% | Feb 19, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in InstantASP InstantForum.NET 4.1.3, 4.1.2, 4.1.1, 4.0.0, 4.1.0, an... |
| CVE-2014-9465 | — | — | 3.4% | Feb 19, 2015 | senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.... |
| CVE-2014-8690 | — | — | 4.0% | Feb 19, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an... |
| CVE-2014-8165 | — | — | 2.8% | Feb 19, 2015 | scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote ... |
| CVE-2014-1832 | — | — | 0.4% | Feb 19, 2015 | Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) contro... |
| CVE-2014-1831 | — | — | 0.4% | Feb 19, 2015 | Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1)... |
| CVE-2014-9423 | — | — | 3.9% | Feb 19, 2015 | The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5... |
| CVE-2014-9422 | — | — | 2.7% | Feb 19, 2015 | The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1... |
| CVE-2014-9421 | — | — | 6.2% | Feb 19, 2015 | The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x t... |
| CVE-2014-6304 | — | — | 1.2% | Feb 19, 2015 | The Form Controls CSS file in PNMsoft Sequence Kinetics before 7.7 allows remote attackers to obtain sensitive source-co... |
| CVE-2014-6303 | — | — | 1.2% | Feb 19, 2015 | The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 do not properly detect recursion during enti... |
| CVE-2014-6302 | — | — | 1.3% | Feb 19, 2015 | The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 allow remote attackers to read arbitrary fil... |
| CVE-2014-6301 | — | — | 0.9% | Feb 19, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the tables-management module in PNMsoft Sequence Kinetics before ... |
| CVE-2014-5352 | — | — | 6.2% | Feb 19, 2015 | The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in ... |
| CVE-2014-6147 | — | — | 0.4% | Feb 19, 2015 | IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sens... |
| CVE-2014-5286 | — | — | 1.4% | Feb 19, 2015 | The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix ... |
| CVE-2014-9466 | — | — | 2.1% | Feb 17, 2015 | Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does no... |
| CVE-2014-8757 | — | — | 4.5% | Feb 17, 2015 | LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request. |
| CVE-2014-8023 | — | — | 1.8% | Feb 17, 2015 | Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, do... |
| CVE-2014-6194 | — | — | 1.4% | Feb 17, 2015 | Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5... |
| CVE-2014-6102 | — | — | 0.5% | Feb 17, 2015 | IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX008, Maximo Asset Management 7.5.0 through... |
| CVE-2014-9375 | — | — | 3.2% | Feb 16, 2015 | Directory traversal vulnerability in the LibraryFileUploadServlet servlet in Lexmark Markvision Enterprise allows remote... |
| CVE-2014-6137 | — | — | 2.3% | Feb 16, 2015 | Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229... |
| CVE-2014-6113 | — | — | 0.9% | Feb 16, 2015 | Cross-site scripting (XSS) vulnerability in the Web Reports component in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now