CVE Vulnerabilities in 2014

7 documented vulnerabilities published in 2014.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2014

All CVEs from 2014

CVE-2014-3566
3.4 low

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Redhat Enterprise Linux Oct 15, 2014
CVE-2014-5455
5.3 medium

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

Openvpn Openvpn Aug 25, 2014
CVE-2014-2653
6.5 medium

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

Openbsd Openssh Mar 27, 2014
CVE-2014-2532
4.2 medium

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

Oracle Communications User Data Repository Mar 18, 2014
CVE-2014-0759
5.9 medium

Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

Schneider-Electric Floating License Manager Feb 28, 2014
CVE-2011-4327
5.5 medium

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.

Openbsd Openssh Feb 3, 2014
CVE-2014-1692
7.3 high

The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does not initialize certain data structures, which might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via vectors tha

Openbsd Openssh Jan 29, 2014