2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7170 | — | — | 0.2% | Dec 17, 2014 | Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between pack... |
| CVE-2014-9253 | — | — | 2.4% | Dec 17, 2014 | The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allo... |
| CVE-2014-5438 | — | — | 0.8% | Dec 17, 2014 | Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and ea... |
| CVE-2014-5437 | — | — | 0.6% | Dec 17, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware... |
| CVE-2014-7880 | — | — | 2.3% | Dec 17, 2014 | Multiple unspecified vulnerabilities in the POP implementation in HP OpenVMS TCP/IP 5.7 before ECO5 allow remote attacke... |
| CVE-2014-7285 | — | — | 50.3% | Dec 17, 2014 | The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe... |
| CVE-2014-8133 | — | — | 0.6% | Dec 17, 2014 | arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local u... |
| CVE-2014-4626 | — | — | 4.0% | Dec 17, 2014 | EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote a... |
| CVE-2014-8006 | — | — | 1.2% | Dec 17, 2014 | The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass... |
| CVE-2014-6182 | — | — | 2.1% | Dec 17, 2014 | Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.... |
| CVE-2014-4844 | — | — | 1.2% | Dec 17, 2014 | The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and ... |
| CVE-2014-8248 | — | — | 1.6% | Dec 16, 2014 | SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows re... |
| CVE-2014-8247 | — | — | 1.8% | Dec 16, 2014 | Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b... |
| CVE-2014-8246 | — | — | 0.9% | Dec 16, 2014 | Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before ... |
| CVE-2014-6176 | — | — | 1.8% | Dec 16, 2014 | IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x thro... |
| CVE-2014-5354 | — | — | 1.7% | Dec 16, 2014 | plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KD... |
| CVE-2014-5353 | — | — | 5.0% | Dec 16, 2014 | The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (... |
| CVE-2014-9373 | — | — | 6.3% | Dec 16, 2014 | Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote... |
| CVE-2014-9372 | — | — | 1.6% | Dec 16, 2014 | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) befo... |
| CVE-2014-9371 | — | — | 19.1% | Dec 16, 2014 | The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code ... |
| CVE-2014-9358 | — | — | 2.5% | Dec 16, 2014 | Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attack... |
| CVE-2014-9357 | — | — | 6.5% | Dec 16, 2014 | Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build... |
| CVE-2014-9323 | — | — | 2.9% | Dec 16, 2014 | The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a de... |
| CVE-2014-9057 | — | — | 2.0% | Dec 16, 2014 | SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.... |
| CVE-2014-8964 | — | — | 6.5% | Dec 16, 2014 | Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now