{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T12:01:38Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20140115-CVE-2014-0666","slug":"cisco-sa-20140115-cve-2014-0666","vendor":"Cisco","title":"Cisco Jabber for Windows Remote Code Execution Vulnerability","summary":"A vulnerability in the Send Screen Capture function of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to install arbitrary files on a targeted system. The vulnerability is due to insufficient validation of data in the packets sent via the send screen capture functionality. An attacker could exploit this vulnerability by crafting or altering the packets sent as part of a send screen capture that would result in an uncontrolled directory traversal and/or acceptance of non-graphic type files. An exploit could allow the attacker to potentially execute arbitrary code on the Windows machine with the privileges of the installed Cisco Jabber for Windows client software. Cisco has confirmed the vulnerability in a security notice and released software updates. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.","severity":"Medium","published_at":"2014-01-15T22:43:55Z","updated_at":"2014-01-15T22:43:55Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20140115-CVE-2014-0666","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20140115-CVE-2014-0666/csaf/Cisco-SA-20140115-CVE-2014-0666.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.05536},"cves":[{"id":"CVE-2014-0666","kev":false,"epss":{"score":0.05536,"percentile":0.91949,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"}}],"public_evidence":[{"product":{"name":"Cisco Jabber for Windows","slug":"cisco-jabber-for-windows","vendor":"Cisco"},"cve":{"id":"CVE-2014-0666"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:08:27Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Jabber for Windows","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.05536,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"},"published_at":"2014-01-15T22:43:55Z","updated_at":"2014-01-15T22:43:55Z","advisory_updated_at":"2014-01-15T22:43:55Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20140115-CVE-2014-0666","row_display_order":1}]}