CVE-2018-0483
- EPSS 0.18%
- Published 10.01.2019 17:29:00
- Last modified 21.11.2024 03:38:19
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supp...
CVE-2018-0449
- EPSS 0.04%
- Published 10.01.2019 16:29:00
- Last modified 21.11.2024 03:38:15
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated privileges. The...
CVE-2018-0201
- EPSS 0.24%
- Published 22.02.2018 00:29:00
- Last modified 21.11.2024 03:37:43
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of input dur...
CVE-2018-0199
- EPSS 0.48%
- Published 22.02.2018 00:29:00
- Last modified 21.11.2024 03:37:42
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of script ...
CVE-2017-12358
- EPSS 0.17%
- Published 30.11.2017 09:29:01
- Last modified 20.04.2025 01:37:25
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface...
CVE-2017-12356
- EPSS 0.17%
- Published 30.11.2017 09:29:01
- Last modified 20.04.2025 01:37:25
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interfa...
CVE-2017-12286
- EPSS 0.08%
- Published 19.10.2017 08:29:00
- Last modified 20.04.2025 01:37:25
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is du...
CVE-2014-0666
- EPSS 13.45%
- Published 16.01.2014 19:55:04
- Last modified 11.04.2025 00:51:21
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka ...
CVE-2013-1228
- EPSS 0.14%
- Published 06.09.2013 11:15:37
- Last modified 11.04.2025 00:51:21
Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.
- EPSS 0.47%
- Published 26.06.2013 19:55:01
- Last modified 11.04.2025 00:51:21
The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60...