2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8007 | — | — | 1.3% | Dec 20, 2014 | Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML so... |
| CVE-2014-3410 | — | — | 1.1% | Dec 20, 2014 | The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an... |
| CVE-2014-5213 | — | — | 2.0% | Dec 19, 2014 | nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allo... |
| CVE-2014-5212 | — | — | 2.0% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allo... |
| CVE-2014-9408 | — | — | 2.2% | Dec 19, 2014 | Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activat... |
| CVE-2014-9407 | — | — | 0.6% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.0.5 allow remote attackers to hij... |
| CVE-2014-9403 | — | — | 2.2% | Dec 19, 2014 | The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause... |
| CVE-2014-9381 | — | — | 2.8% | Dec 19, 2014 | Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers ... |
| CVE-2014-9380 | — | — | 2.4% | Dec 19, 2014 | The dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service... |
| CVE-2014-9379 | — | — | 4.0% | Dec 19, 2014 | The radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows r... |
| CVE-2014-9378 | — | — | 3.9% | Dec 19, 2014 | Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (cras... |
| CVE-2014-9377 | — | — | 4.0% | Dec 19, 2014 | Heap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c in Ettercap 0.8.1 allows remot... |
| CVE-2014-9376 | — | — | 4.1% | Dec 19, 2014 | Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possi... |
| CVE-2014-9368 | — | — | 1.0% | Dec 19, 2014 | Cross-site request forgery (CSRF) vulnerability in the twitterDash plugin 2.1 and earlier for WordPress allows remote at... |
| CVE-2014-9355 | — | — | 0.6% | Dec 19, 2014 | Puppet Enterprise before 3.7.1 allows remote authenticated users to obtain licensing and certificate signing request inf... |
| CVE-2014-9341 | — | — | 1.0% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the yURL ReTwitt plugin 1.4 and earlier for WordPress allo... |
| CVE-2014-9340 | — | — | 1.0% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the wpCommentTwit plugin 0.5 and earlier for WordPress all... |
| CVE-2014-9339 | — | — | 1.0% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the SPNbabble plugin 1.4.1 and earlier for WordPress allow... |
| CVE-2014-9338 | — | — | 1.0% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the O2Tweet plugin 0.0.4 and earlier for WordPress allow r... |
| CVE-2014-9337 | — | — | 1.0% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Mikiurl Wordpress Eklentisi plugin 2.0 and earlier for... |
| CVE-2014-9336 | — | — | 1.0% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the iTwitter plugin 0.04 and earlier for WordPress allow r... |
| CVE-2014-9335 | — | — | 1.0% | Dec 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the DandyID Services plugin 1.5.9 and earlier for WordPres... |
| CVE-2014-9324 | — | — | 1.8% | Dec 19, 2014 | The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote au... |
| CVE-2014-9258 | — | — | 3.2% | Dec 19, 2014 | SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to exec... |
| CVE-2014-9185 | — | — | 2.1% | Dec 19, 2014 | Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitra... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now