AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-2227

MEDIUM · CVSS 6 EPSS 2.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-07-25 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-2227
Severity
MEDIUM
CVSS
6
EPSS
2.17%

Original Filing — NVD Description

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.