CVE-2014-0666
published 2014-01-16CVE-2014-0666: Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload…
PriorityP337medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.54%
91.9th percentile
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | jabber | <= 9.2\(.1\) | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.2HIGH
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
php: insecure default permissions on the FPM unix socket
vendor_redhat·2014-04-30·CVSS 7.2
CVE-2014-0185 [HIGH] php: insecure default permissions on the FPM unix socket
php: insecure default permissions on the FPM unix socket
sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.
Statement: This issue did not affect the php and php53 packages as shipped with Red Hat Enterprise Linux 5. This issue is not planned to be addressed in the php packages in Red Hat Enterprise Linux 6 and 7. Refer to https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0185 for further details.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Wi
Cisco
Cisco Jabber for Windows Remote Code Execution Vulnerability
vendor_cisco·2014-01-15·CVSS 4.3
CVE-2014-0666 [MEDIUM] CWE-22 Cisco Jabber for Windows Remote Code Execution Vulnerability
Cisco Jabber for Windows Remote Code Execution Vulnerability
A vulnerability in the Send Screen Capture function of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to install arbitrary files on a targeted system.
The vulnerability is due to insufficient validation of data in the packets sent via the send screen capture functionality. An attacker could exploit this vulnerability by crafting or altering the packets sent as part of a send screen capture that would result in an uncontrolled directory traversal and/or acceptance of non-graphic type files. An exploit could allow the attacker to potentially execute arbitrary code on the Windows machine with the privileges of the installed Cisco Jabber for Windows client software.
Cisco has confirmed the vulnerability i
GHSA
GHSA-75rf-hx73-vjfr: Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9
ghsa_unreviewed·2022-05-17
CVE-2014-0666 [MEDIUM] CWE-22 GHSA-75rf-hx73-vjfr: Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056.
No detection rules found.
No public exploits indexed.
http://osvdb.org/102122http://secunia.com/advisories/56331http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0666http://tools.cisco.com/security/center/viewAlert.x?alertId=32451http://www.securityfocus.com/bid/64965http://www.securitytracker.com/id/1029635https://exchange.xforce.ibmcloud.com/vulnerabilities/90435http://osvdb.org/102122http://secunia.com/advisories/56331http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0666http://tools.cisco.com/security/center/viewAlert.x?alertId=32451http://www.securityfocus.com/bid/64965http://www.securitytracker.com/id/1029635https://exchange.xforce.ibmcloud.com/vulnerabilities/90435
2014-01-16
Published