CVE-2023-28599
- EPSS 0.4%
- Veröffentlicht 13.06.2023 17:15:14
- Zuletzt bearbeitet 21.11.2024 07:55:38
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
CVE-2023-28598
- EPSS 0.3%
- Veröffentlicht 13.06.2023 17:15:14
- Zuletzt bearbeitet 21.11.2024 07:55:38
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.
CVE-2023-28597
- EPSS 0.85%
- Veröffentlicht 27.03.2023 21:15:12
- Zuletzt bearbeitet 19.02.2025 16:15:37
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network...
CVE-2023-22882
- EPSS 0.56%
- Veröffentlicht 16.03.2023 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:45:34
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
CVE-2023-22881
- EPSS 0.43%
- Veröffentlicht 16.03.2023 21:15:12
- Zuletzt bearbeitet 21.11.2024 07:45:34
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
CVE-2023-22880
- EPSS 0.37%
- Veröffentlicht 16.03.2023 21:15:12
- Zuletzt bearbeitet 21.11.2024 07:45:34
Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtim...
CVE-2022-36928
- EPSS 0.2%
- Veröffentlicht 09.01.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:14:06
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.
CVE-2022-28755
- EPSS 0.48%
- Veröffentlicht 11.08.2022 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:57:52
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitr...
CVE-2021-28133
- EPSS 2.29%
- Veröffentlicht 18.03.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:59:09
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share...
CVE-2020-6110
- EPSS 1.1%
- Veröffentlicht 08.06.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:07
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achie...