2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9607 | MEDIUM | 6.1 | 5.5% | Feb 19, 2020 | Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote... |
| CVE-2014-9606 | MEDIUM | 6.1 | 4.3% | Feb 19, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.... |
| CVE-2014-2727 | CRITICAL | 9.8 | 1.9% | Feb 19, 2020 | The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection. |
| CVE-2014-2228 | CRITICAL | 9.8 | 3.2% | Feb 19, 2020 | The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe dese... |
| CVE-2014-3622 | CRITICAL | 9.8 | 3.1% | Feb 19, 2020 | Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might a... |
| CVE-2014-3879 | CRITICAL | 9.8 | 2.7% | Feb 18, 2020 | OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a po... |
| CVE-2014-4967 | CRITICAL | 9.8 | 3.4% | Feb 18, 2020 | Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by ... |
| CVE-2014-4966 | CRITICAL | 9.8 | 3.4% | Feb 18, 2020 | Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data... |
| CVE-2014-4651 | CRITICAL | 9.8 | 2.1% | Feb 18, 2020 | It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attack... |
| CVE-2014-8089 | CRITICAL | 9.8 | 2.5% | Feb 17, 2020 | SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the ... |
| CVE-2014-7236 | CRITICAL | 9.1 | 55.6% | Feb 17, 2020 | Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary ... |
| CVE-2014-4981 | CRITICAL | 9.8 | 6.2% | Feb 17, 2020 | LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization... |
| CVE-2014-1947 | HIGH | 7.8 | 6.9% | Feb 17, 2020 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote... |
| CVE-2014-9404 | — | — | — | Feb 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5005. Reason: This candidate is a reservation du... |
| CVE-2014-1617 | MEDIUM | 6.5 | 1.0% | Feb 13, 2020 | Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of ser... |
| CVE-2014-3208 | HIGH | 7.5 | 1.5% | Feb 13, 2020 | A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery), |
| CVE-2014-4198 | CRITICAL | 9.1 | 1.3% | Feb 13, 2020 | A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that ... |
| CVE-2014-4170 | CRITICAL | 9.8 | 14.1% | Feb 13, 2020 | A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restric... |
| CVE-2014-3919 | CRITICAL | 9.3 | 0.9% | Feb 13, 2020 | A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspec... |
| CVE-2014-3860 | HIGH | 7.8 | 0.7% | Feb 12, 2020 | Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability |
| CVE-2014-4607 | HIGH | 8.8 | 5.3% | Feb 12, 2020 | Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow... |
| CVE-2014-2560 | HIGH | 7.5 | 1.7% | Feb 12, 2020 | The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which... |
| CVE-2014-8128 | MEDIUM | 6.5 | 3.8% | Feb 12, 2020 | LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attack... |
| CVE-2014-9390 | CRITICAL | 9.8 | 63.2% | Feb 12, 2020 | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS... |
| CVE-2014-6262 | HIGH | 7.5 | 7.1% | Feb 12, 2020 | Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other pr... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now