2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-8751——Multiple cross-site scripting (XSS) vulnerabilities in goYWP WebPress 13.00.06 allow remote attackers to inject arbitrar...
CVE-2014-8583——mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges c...
CVE-2014-8340——SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to ...
CVE-2014-8118——Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in ...
CVE-2014-5466——Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x b...
CVE-2014-5359——Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard)...
CVE-2014-4936——The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)...
CVE-2014-9386——Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote att...
CVE-2014-9385——Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the au...
CVE-2014-9252——Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain...
CVE-2014-9251——Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attack...
CVE-2014-9250——Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, wh...
CVE-2014-9249——The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by conn...
CVE-2014-9248——Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain ac...
CVE-2014-9247——Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address,...
CVE-2014-9246——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9385, CVE-2014-9386. Reason: this ID was inten...
CVE-2014-9245——Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename acti...
CVE-2014-8967——Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a craf...
CVE-2014-8610——AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which...
CVE-2014-8609——The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Androi...
CVE-2014-8507——Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap...
CVE-2014-7911——luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0....
CVE-2014-6261——Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to...
CVE-2014-6260——Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote att...
CVE-2014-6259——Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers t...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now