2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9607MEDIUM6.1Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote...
CVE-2014-9606MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4....
CVE-2014-2727CRITICAL9.8The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
CVE-2014-2228CRITICAL9.8The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe dese...
CVE-2014-3622CRITICAL9.8Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might a...
CVE-2014-3879CRITICAL9.8OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a po...
CVE-2014-4967CRITICAL9.8Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by ...
CVE-2014-4966CRITICAL9.8Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data...
CVE-2014-4651CRITICAL9.8It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attack...
CVE-2014-8089CRITICAL9.8SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the ...
CVE-2014-7236CRITICAL9.1Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary ...
CVE-2014-4981CRITICAL9.8LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization...
CVE-2014-1947HIGH7.8Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote...
CVE-2014-9404Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5005. Reason: This candidate is a reservation du...
CVE-2014-1617MEDIUM6.5Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of ser...
CVE-2014-3208HIGH7.5A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery),
CVE-2014-4198CRITICAL9.1A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that ...
CVE-2014-4170CRITICAL9.8A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restric...
CVE-2014-3919CRITICAL9.3A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspec...
CVE-2014-3860HIGH7.8Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability
CVE-2014-4607HIGH8.8Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow...
CVE-2014-2560HIGH7.5The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which...
CVE-2014-8128MEDIUM6.5LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attack...
CVE-2014-9390CRITICAL9.8Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS...
CVE-2014-6262HIGH7.5Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other pr...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now