2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2274 | — | — | 0.9% | Mar 19, 2018 | Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress... |
| CVE-2014-3626 | — | — | 1.7% | Mar 19, 2018 | The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other componen... |
| CVE-2014-4613 | — | — | 3.2% | Mar 16, 2018 | Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke... |
| CVE-2014-4612 | — | — | 1.4% | Mar 16, 2018 | Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5... |
| CVE-2014-8130 | — | — | 3.9% | Mar 12, 2018 | The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to ca... |
| CVE-2014-8129 | — | — | 3.9% | Mar 12, 2018 | LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified ot... |
| CVE-2014-6617 | — | — | 4.5% | Mar 9, 2018 | Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, whi... |
| CVE-2014-4861 | — | — | 1.2% | Mar 9, 2018 | The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that ... |
| CVE-2014-2592 | — | — | 2.3% | Mar 9, 2018 | Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code ... |
| CVE-2014-7272 | — | — | 0.4% | Mar 8, 2018 | Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as r... |
| CVE-2014-7271 | — | — | 0.4% | Mar 8, 2018 | Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. |
| CVE-2014-8780 | — | — | 0.7% | Mar 7, 2018 | Cross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script ... |
| CVE-2014-5044 | — | — | 5.9% | Mar 7, 2018 | Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of se... |
| CVE-2014-10072 | — | — | 2.7% | Feb 27, 2018 | In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links. |
| CVE-2014-10071 | — | — | 2.8% | Feb 27, 2018 | In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax. |
| CVE-2014-10070 | — | — | 0.5% | Feb 27, 2018 | zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of ... |
| CVE-2014-3206 | — | — | 52.9% | Feb 23, 2018 | Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmg... |
| CVE-2014-3205 | — | — | 2.9% | Feb 23, 2018 | backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a ... |
| CVE-2014-3972 | — | — | 2.5% | Feb 19, 2018 | Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers ... |
| CVE-2014-0014 | — | — | 1.4% | Feb 15, 2018 | Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 a... |
| CVE-2014-0013 | — | — | 0.7% | Feb 15, 2018 | Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 a... |
| CVE-2014-8171 | — | — | 0.4% | Feb 9, 2018 | The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock... |
| CVE-2014-3219 | — | — | 0.4% | Feb 9, 2018 | fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp... |
| CVE-2014-8985 | — | — | 10.0% | Feb 8, 2018 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co... |
| CVE-2014-4145 | — | — | 8.9% | Feb 8, 2018 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now