{"api_version":"1","generated_at":"2026-07-23T08:05:50+00:00","cve":"CVE-2014-2966","urls":{"html":"https://cve.report/CVE-2014-2966","api":"https://cve.report/api/cve/CVE-2014-2966.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2966","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2966"},"summary":{"title":"CVE-2014-2966","description":"The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.","state":"PUBLISHED","assigner":"certcc","published_at":"2014-07-26 15:55:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-20","CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/162308","name":"http://www.kb.cert.org/vuls/id/162308","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"VU#162308 - Resin Pro improperly performs Unicode transformations","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://caucho.com/products/resin/download#download","name":"http://caucho.com/products/resin/download#download","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Resin Pro Download | Caucho","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2966","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2966","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"2966","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"caucho","cpe5":"resin","cpe6":"4.0.36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"professional","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2966","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"caucho","cpe5":"resin","cpe6":"4.0.37","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"professional","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2966","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"caucho","cpe5":"resin","cpe6":"4.0.38","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"professional","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2966","vulnerable":"1","versionEndIncluding":"4.0.39","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"caucho","cpe5":"resin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"professional","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:28:46.194Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#162308","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/162308"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://caucho.com/products/resin/download#download"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-07-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-07-26T14:57:00.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#162308","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/162308"},{"tags":["x_refsource_CONFIRM"],"url":"http://caucho.com/products/resin/download#download"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2014-2966","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#162308","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/162308"},{"name":"http://caucho.com/products/resin/download#download","refsource":"CONFIRM","url":"http://caucho.com/products/resin/download#download"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2014-2966","datePublished":"2014-07-26T15:00:00.000Z","dateReserved":"2014-04-21T00:00:00.000Z","dateUpdated":"2024-08-06T10:28:46.194Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-07-26 15:55:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-20","CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:caucho:resin:*:*:*:*:professional:*:*:*","versionEndIncluding":"4.0.39","matchCriteriaId":"CF911461-9047-43E3-88FA-FDBD80EDBBAF"},{"vulnerable":true,"criteria":"cpe:2.3:a:caucho:resin:4.0.36:*:*:*:professional:*:*:*","matchCriteriaId":"5ADC8207-50CE-4787-B858-CDC8942059A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:caucho:resin:4.0.37:*:*:*:professional:*:*:*","matchCriteriaId":"7883A7C0-4477-4344-882C-0861A25AB384"},{"vulnerable":true,"criteria":"cpe:2.3:a:caucho:resin:4.0.38:*:*:*:professional:*:*:*","matchCriteriaId":"4DD1E629-560A-44A9-B246-FAC290B57650"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2966","Ordinal":"1","Title":"CVE-2014-2966","CVE":"CVE-2014-2966","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2966","Ordinal":"1","NoteData":"The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.","Type":"Description","Title":"CVE-2014-2966"},{"CveYear":"2014","CveId":"2966","Ordinal":"2","NoteData":"2014-07-26","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2966","Ordinal":"3","NoteData":"2014-07-26","Type":"Other","Title":"Modified"}]}}}