2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-8751Multiple cross-site scripting (XSS) vulnerabilities in goYWP WebPress 13.00.06 allow remote attackers to inject arbitrar...
CVE-2014-8583mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges c...
CVE-2014-8340SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to ...
CVE-2014-8118Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in ...
CVE-2014-5466Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x b...
CVE-2014-5359Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard)...
CVE-2014-4936The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)...
CVE-2014-9386Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote att...
CVE-2014-9385Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the au...
CVE-2014-9252Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain...
CVE-2014-9251Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attack...
CVE-2014-9250Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, wh...
CVE-2014-9249The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by conn...
CVE-2014-9248Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain ac...
CVE-2014-9247Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address,...
CVE-2014-9246Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9385, CVE-2014-9386. Reason: this ID was inten...
CVE-2014-9245Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename acti...
CVE-2014-8967Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a craf...
CVE-2014-8610AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which...
CVE-2014-8609The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Androi...
CVE-2014-8507Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap...
CVE-2014-7911luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0....
CVE-2014-6261Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to...
CVE-2014-6260Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote att...
CVE-2014-6259Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers t...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now