CVE-2014-0666
Summary
| CVE | CVE-2014-0666 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-16 19:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS: 0.103640000 probability, percentile 0.932320000 (date 2026-05-03)
Problem Types: CWE-22 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Jabber | 9.0 | - | - | All |
| Application | Cisco | Jabber | 9.0\(.0\) | - | - | All |
| Application | Cisco | Jabber | 9.0\(.1\) | - | - | All |
| Application | Cisco | Jabber | 9.0\(.2\) | - | - | All |
| Application | Cisco | Jabber | 9.0\(.3\) | - | - | All |
| Application | Cisco | Jabber | 9.0\(.4\) | - | - | All |
| Application | Cisco | Jabber | 9.0\(.5\) | - | - | All |
| Application | Cisco | Jabber | 9.1 | - | - | All |
| Application | Cisco | Jabber | 9.1\(.0\) | - | - | All |
| Application | Cisco | Jabber | 9.1\(.1\) | - | - | All |
| Application | Cisco | Jabber | 9.1\(.2\) | - | - | All |
| Application | Cisco | Jabber | 9.1\(.3\) | - | - | All |
| Application | Cisco | Jabber | 9.1\(.4\) | - | - | All |
| Application | Cisco | Jabber | 9.1\(.5\) | - | - | All |
| Application | Cisco | Jabber | 9.2 | - | - | All |
| Application | Cisco | Jabber | 9.2\(.0\) | - | - | All |
| Application | Cisco | Jabber | All | - | - | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Jabber for Windows Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Jabber for Windows Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Jabber for Windows CVE-2014-0666 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Jabber for Windows Bug in Send Screen Capture Feature Lets Remote Users Install Arbitrary Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Security Advisory SA56331 - Cisco Jabber for Windows Send Screen Capture Directory Traversal Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/102122 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.