VYPR

Zoom Clients

by Zoom Video Communications, Inc.

CVEs (27)

  • CVE-2026-53415HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

  • CVE-2026-53413HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

  • CVE-2023-28597HigMar 27, 2023
    risk 0.54cvss 8.3epss 0.01

    Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could…

  • CVE-2024-24697HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-39215HigSep 12, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-36535HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.01

    Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

  • CVE-2026-53414MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

  • CVE-2025-49464MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.01

    Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

  • CVE-2024-24699MedFeb 14, 2024
    risk 0.42cvss 6.5epss 0.02

    Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

  • CVE-2023-49646MedDec 13, 2023
    risk 0.42cvss 6.4epss 0.00

    Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-22882MedMar 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.

  • CVE-2023-22881MedMar 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.

  • CVE-2023-39218MedAug 8, 2023
    risk 0.40cvss 6.1epss 0.01

    Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

  • CVE-2023-36532MedAug 8, 2023
    risk 0.38cvss 5.9epss 0.02

    Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

  • CVE-2023-43582MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

  • CVE-2024-24690MedFeb 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2025-62483MedNov 13, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2023-36539MedJun 30, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

  • CVE-2024-24698MedFeb 14, 2024
    risk 0.32cvss 4.9epss 0.01

    Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

  • CVE-2023-39199MedNov 14, 2023
    risk 0.32cvss 4.9epss 0.01

    Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

Page 1 of 2