VYPR

Zoom

by Zoom Video Communications, Inc.

CVEs (66)

  • CVE-2023-39218MedAug 8, 2023
    risk 0.40cvss 6.1epss 0.01

    Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

  • CVE-2022-36928MedJan 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.

  • CVE-2022-22787MedMay 18, 2022
    risk 0.39cvss 5.9epss 0.04

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting users client to connect to a…

  • CVE-2024-24694MedApr 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-39209MedAug 8, 2023
    risk 0.38cvss 5.9epss 0.01

    Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

  • CVE-2023-36532MedAug 8, 2023
    risk 0.38cvss 5.9epss 0.02

    Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

  • CVE-2024-27247MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

  • CVE-2023-43582MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

  • CVE-2024-24690MedFeb 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-36539MedJun 30, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

  • CVE-2023-28600MedJun 13, 2023
    risk 0.34cvss 5.2epss 0.00

    Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.

  • CVE-2024-24698MedFeb 14, 2024
    risk 0.32cvss 4.9epss 0.01

    Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

  • CVE-2023-43583MedDec 13, 2023
    risk 0.32cvss 4.9epss 0.01

    Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.

  • CVE-2023-39199MedNov 14, 2023
    risk 0.32cvss 4.9epss 0.01

    Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

  • CVE-2021-34420MedNov 11, 2021
    risk 0.31cvss 4.7epss 0.00

    The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.

  • CVE-2021-28133MedMar 18, 2021
    risk 0.29cvss 4.3epss 0.16

    Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other…

  • CVE-2023-39205MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-39204MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

  • CVE-2023-39203MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2023-28599MedJun 13, 2023
    risk 0.28cvss 4.3epss 0.01

    Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.