{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T13:07:54.619","vulnerabilities":[{"cve":{"id":"CVE-2014-0771","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2014-04-12T04:37:31.643","lastModified":"2026-06-17T00:03:36.767","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The BWOCXRUN.BwocxrunCtrl.1 control contains a method named \n“OpenUrlToBuffer.” This method takes a URL as a parameter and returns \nits contents to the caller in JavaScript. The URLs are accessed in the \nsecurity context of the current browser session. The control does not \nperform any URL validation and allows “file://” URLs that access the \nlocal disk.\n\n\nThe method can be used to open a URL (including file URLs) and read \nfile URLs through JavaScript. This method could also be used to reach \nany arbitrary URL to which the browser has access."},{"lang":"es","value":"El método OpenUrlToBuffer en el control BWOCXRUN.BwocxrunCtrl.1 ActiveX en bwocxrun.ocx en Advantech WebAccess anterior a 7.2 permite a atacantes remotos leer archivos arbitrarios a través de un fichero: URL."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Advantech","product":"WebAccess","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.1","versionType":"custom","status":"affected"},{"version":"7.2","status":"unaffected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-538"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1","matchCriteriaId":"3D097D1E-9A02-40B0-93BD-163A11638118"},{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:5.0:*:*:*:*:*:*:*","matchCriteriaId":"090C819C-5964-4158-80E6-2D4751A5E8BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:6.0:*:*:*:*:*:*:*","matchCriteriaId":"7CF61F9C-360A-4B70-951D-8EE9CF6E55FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:advantech:advantech_webaccess:7.0:*:*:*:*:*:*:*","matchCriteriaId":"1082E1D5-AF49-431F-9172-98C2D2887C96"}]}]}],"references":[{"url":"http://webaccess.advantech.com/","source":"ics-cert@hq.dhs.gov"},{"url":"http://www.securityfocus.com/bid/66740","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-079-03","source":"ics-cert@hq.dhs.gov"},{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"]}]}}]}