CVE-2014-2134 describes a heap-based buffer overflow vulnerability in the Cisco WebEx Recording Format (WRF) player, affecting versions T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through memory corruption and application crashes by providing a specially crafted .wrf file containing a malicious audio channel. With a CVSS score of 9.3, this vulnerability is considered critical due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
t27ldCPE matchmatch criteria | cpe:2.3:a:cisco:webex_advanced_recording_format_player:t27ld:*:*:*:*:*:*:* | ||
t28CPE matchmatch criteria | cpe:2.3:a:cisco:webex_advanced_recording_format_player:t28:*:*:*:*:*:*:* | ||
t29CPE matchmatch criteria | cpe:2.3:a:cisco:webex_advanced_recording_format_player:t29:*:*:*:*:*:*:* | ||
t27ldCPE matchmatch criteria | cpe:2.3:a:cisco:webex_recording_format_player:t27ld:*:*:*:*:*:*:* | ||
t28CPE matchmatch criteria | cpe:2.3:a:cisco:webex_recording_format_player:t28:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.