2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8751 | — | — | 1.4% | Dec 16, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in goYWP WebPress 13.00.06 allow remote attackers to inject arbitrar... |
| CVE-2014-8583 | — | — | 0.4% | Dec 16, 2014 | mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges c... |
| CVE-2014-8340 | — | — | 1.8% | Dec 16, 2014 | SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to ... |
| CVE-2014-8118 | — | — | 7.6% | Dec 16, 2014 | Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in ... |
| CVE-2014-5466 | — | — | 0.9% | Dec 16, 2014 | Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x b... |
| CVE-2014-5359 | — | — | 3.8% | Dec 16, 2014 | Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard)... |
| CVE-2014-4936 | — | — | 16.8% | Dec 16, 2014 | The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)... |
| CVE-2014-9386 | — | — | 2.0% | Dec 15, 2014 | Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote att... |
| CVE-2014-9385 | — | — | 1.2% | Dec 15, 2014 | Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the au... |
| CVE-2014-9252 | — | — | 0.4% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain... |
| CVE-2014-9251 | — | — | 1.3% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attack... |
| CVE-2014-9250 | — | — | 1.5% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, wh... |
| CVE-2014-9249 | — | — | 1.6% | Dec 15, 2014 | The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by conn... |
| CVE-2014-9248 | — | — | 1.2% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain ac... |
| CVE-2014-9247 | — | — | 1.1% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address,... |
| CVE-2014-9246 | — | — | — | Dec 15, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9385, CVE-2014-9386. Reason: this ID was inten... |
| CVE-2014-9245 | — | — | 1.4% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename acti... |
| CVE-2014-8967 | — | — | 12.4% | Dec 15, 2014 | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a craf... |
| CVE-2014-8610 | — | — | 0.3% | Dec 15, 2014 | AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which... |
| CVE-2014-8609 | — | — | 0.6% | Dec 15, 2014 | The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Androi... |
| CVE-2014-8507 | — | — | 1.6% | Dec 15, 2014 | Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap... |
| CVE-2014-7911 | — | — | 24.3% | Dec 15, 2014 | luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.... |
| CVE-2014-6261 | — | — | 19.7% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to... |
| CVE-2014-6260 | — | — | 1.8% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote att... |
| CVE-2014-6259 | — | — | 1.6% | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers t... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now