2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-7174MEDIUM5.3FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.
CVE-2014-7173CRITICAL9.8FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx2...
CVE-2014-1423MEDIUM5.5signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from quer...
CVE-2014-2723HIGH8.8In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may ...
CVE-2014-2722HIGH8.8In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may ...
CVE-2014-2721HIGH8.8In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may ...
CVE-2014-1634CRITICAL9.8SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subsc...
CVE-2014-7914HIGH8.1btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which al...
CVE-2014-3557Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2014-4019HIGH7.5ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient...
CVE-2014-4650CRITICAL9.8The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path ...
CVE-2014-7951MEDIUM4.6Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate att...
CVE-2014-4659MEDIUM5.5Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credentia...
CVE-2014-4658MEDIUM5.5The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, whic...
CVE-2014-4657CRITICAL9.8The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers...
CVE-2014-3484CRITICAL9.8Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 ...
CVE-2014-4678CRITICAL9.8The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers...
CVE-2014-4660MEDIUM5.5Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list,...
CVE-2014-9617MEDIUM6.1Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to re...
CVE-2014-9615MEDIUM6.1Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or H...
CVE-2014-9614CRITICAL9.8The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it eas...
CVE-2014-9613CRITICAL9.8Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co...
CVE-2014-9612CRITICAL9.8SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1...
CVE-2014-9609MEDIUM5.3Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0...
CVE-2014-9608MEDIUM6.1Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x bef...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now