VYPR

Zoom

by Zoom Video Communications, Inc.

CVEs (66)

  • CVE-2023-43586HigDec 13, 2023
    risk 0.48cvss 7.3epss 0.01

    Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2023-34114HigJun 13, 2023
    risk 0.48cvss 7.4epss 0.01

    Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.

  • CVE-2024-24697HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-36540HigAug 8, 2023
    risk 0.47cvss 7.3epss 0.00

    Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-43585HigDec 13, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2023-39215HigSep 12, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-36535HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.01

    Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

  • CVE-2024-24696MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.01

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2024-24695MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.01

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2023-22880MedMar 16, 2023
    risk 0.44cvss 6.8epss 0.01

    Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom…

  • CVE-2019-13450MedJul 9, 2019
    risk 0.43cvss 6.5epss 0.04

    In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a…

  • CVE-2025-49464MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.01

    Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

  • CVE-2025-49463MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2025-46789MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

  • CVE-2024-24699MedFeb 14, 2024
    risk 0.42cvss 6.5epss 0.02

    Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

  • CVE-2023-49646MedDec 13, 2023
    risk 0.42cvss 6.4epss 0.00

    Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-39208MedSep 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.

  • CVE-2023-22882MedMar 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.

  • CVE-2023-22881MedMar 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.

  • CVE-2019-13449MedJul 9, 2019
    risk 0.42cvss 6.5epss 0.02

    In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.