2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-2274Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress...
CVE-2014-3626The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other componen...
CVE-2014-4613Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke...
CVE-2014-4612Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5...
CVE-2014-8130The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to ca...
CVE-2014-8129LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified ot...
CVE-2014-6617Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, whi...
CVE-2014-4861The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that ...
CVE-2014-2592Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code ...
CVE-2014-7272Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as r...
CVE-2014-7271Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
CVE-2014-8780Cross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script ...
CVE-2014-5044Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of se...
CVE-2014-10072In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links.
CVE-2014-10071In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
CVE-2014-10070zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of ...
CVE-2014-3206Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmg...
CVE-2014-3205backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a ...
CVE-2014-3972Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers ...
CVE-2014-0014Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 a...
CVE-2014-0013Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 a...
CVE-2014-8171The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock...
CVE-2014-3219fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp...
CVE-2014-8985Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2014-4145Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now