Zoom Clients
by Zoom Video Communications, Inc.
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-64739 | Med | 0.28 | 4.3 | 0.00 | Nov 13, 2025 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. | ||
| CVE-2023-39205 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2023 | Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2023-39204 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2023 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2023-28599 | Med | 0.28 | 4.3 | 0.01 | Jun 13, 2023 | Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation. | ||
| CVE-2023-39206 | Low | 0.24 | 3.7 | 0.01 | Nov 14, 2023 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2025-49462 | Low | 0.23 | 3.5 | 0.00 | Jul 10, 2025 | Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access. | ||
| CVE-2023-43588 | Low | 0.23 | 3.5 | 0.01 | Nov 15, 2023 | Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. |
- risk 0.28cvss 4.3epss 0.00
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
- risk 0.28cvss 4.3epss 0.01
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
- risk 0.28cvss 4.3epss 0.01
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.28cvss 4.3epss 0.01
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
- risk 0.24cvss 3.7epss 0.01
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.23cvss 3.5epss 0.00
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.
- risk 0.23cvss 3.5epss 0.01
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
Page 2 of 2