2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0227 | — | — | 21.0% | Feb 16, 2015 | java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and... |
| CVE-2014-7883 | — | — | 37.0% | Feb 15, 2015 | HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to o... |
| CVE-2014-7196 | — | — | — | Feb 15, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7169. Reason: This candidate is a duplicate of... |
| CVE-2014-8911 | — | — | 0.9% | Feb 14, 2015 | Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 b... |
| CVE-2014-6195 | — | — | 0.4% | Feb 14, 2015 | The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 be... |
| CVE-2014-4804 | — | — | 1.1% | Feb 14, 2015 | Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iF... |
| CVE-2014-8122 | — | — | 2.1% | Feb 13, 2015 | Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from... |
| CVE-2014-7853 | — | — | 1.2% | Feb 13, 2015 | The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.... |
| CVE-2014-7849 | — | — | 1.3% | Feb 13, 2015 | The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 d... |
| CVE-2014-7827 | — | — | 1.7% | Feb 13, 2015 | The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise ... |
| CVE-2014-0154 | — | — | 1.7% | Feb 13, 2015 | oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it ... |
| CVE-2014-0151 | — | — | 0.6% | Feb 13, 2015 | Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the... |
| CVE-2014-8909 | — | — | 1.4% | Feb 13, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 C... |
| CVE-2014-8385 | — | — | 4.0% | Feb 13, 2015 | Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary co... |
| CVE-2014-6185 | — | — | 0.4% | Feb 13, 2015 | dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 ... |
| CVE-2014-6154 | — | — | 3.5% | Feb 13, 2015 | Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Win... |
| CVE-2014-6139 | — | — | 1.0% | Feb 13, 2015 | The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to b... |
| CVE-2014-4813 | — | — | 0.3% | Feb 13, 2015 | Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0... |
| CVE-2014-4803 | — | — | 0.8% | Feb 13, 2015 | CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 befor... |
| CVE-2014-4781 | — | — | 1.2% | Feb 13, 2015 | The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive ... |
| CVE-2014-4771 | — | — | 1.6% | Feb 13, 2015 | IBM WebSphere MQ 7.0.1 before 7.0.1.13, 7.1 before 7.1.0.6, 7.5 before 7.5.0.5, and 8 before 8.0.0.1 allows remote authe... |
| CVE-2014-9512 | — | — | 6.5% | Feb 12, 2015 | rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization pa... |
| CVE-2014-8110 | — | — | 7.1% | Feb 12, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x befor... |
| CVE-2014-3365 | — | — | 1.8% | Feb 12, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow r... |
| CVE-2014-2153 | — | — | 1.8% | Feb 12, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now