CVE-2018-0483
- EPSS 0.18%
- Veröffentlicht 10.01.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:19
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supp...
CVE-2018-0449
- EPSS 0.04%
- Veröffentlicht 10.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:15
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated privileges. The...
CVE-2018-0201
- EPSS 0.24%
- Veröffentlicht 22.02.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:37:43
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of input dur...
CVE-2018-0199
- EPSS 0.48%
- Veröffentlicht 22.02.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:37:42
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of script ...
CVE-2017-12358
- EPSS 0.17%
- Veröffentlicht 30.11.2017 09:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface...
CVE-2017-12356
- EPSS 0.17%
- Veröffentlicht 30.11.2017 09:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interfa...
CVE-2017-12286
- EPSS 0.08%
- Veröffentlicht 19.10.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is du...
CVE-2014-0666
- EPSS 13.45%
- Veröffentlicht 16.01.2014 19:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka ...
CVE-2013-1228
- EPSS 0.14%
- Veröffentlicht 06.09.2013 11:15:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.
- EPSS 0.47%
- Veröffentlicht 26.06.2013 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60...