Video Software Development Kit
by Zoom Video Communications, Inc.
CVEs (22)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-0147 | Hig | 0.57 | 8.8 | 0.01 | Jan 30, 2025 | Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access. | ||
| CVE-2023-49647 | Hig | 0.57 | 8.8 | 0.00 | Jan 12, 2024 | Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access. | ||
| CVE-2024-45421 | Hig | 0.55 | 8.5 | 0.01 | Feb 25, 2025 | Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access. | ||
| CVE-2023-43586 | Hig | 0.48 | 7.3 | 0.01 | Dec 13, 2023 | Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access. | ||
| CVE-2023-43585 | Hig | 0.46 | 7.1 | 0.01 | Dec 13, 2023 | Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access. | ||
| CVE-2023-36533 | Hig | 0.46 | 7.1 | 0.01 | Aug 8, 2023 | Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access. | ||
| CVE-2024-45422 | Med | 0.42 | 6.5 | 0.01 | Nov 19, 2024 | Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2023-49646 | Med | 0.42 | 6.4 | 0.00 | Dec 13, 2023 | Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2024-45417 | Med | 0.39 | 6.0 | 0.00 | Feb 25, 2025 | Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access. | ||
| CVE-2024-45418 | Med | 0.35 | 5.4 | 0.00 | Feb 25, 2025 | Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access. | ||
| CVE-2024-24690 | Med | 0.35 | 5.4 | 0.01 | Feb 14, 2024 | Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2023-39217 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2023 | Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access. | ||
| CVE-2023-36539 | Med | 0.34 | 5.3 | 0.01 | Jun 30, 2023 | Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. | ||
| CVE-2023-43583 | Med | 0.32 | 4.9 | 0.01 | Dec 13, 2023 | Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access. | ||
| CVE-2025-0145 | Med | 0.30 | 4.6 | 0.00 | Jan 30, 2025 | Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access. | ||
| CVE-2025-0143 | Med | 0.28 | 4.3 | 0.00 | Jan 30, 2025 | Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access. | ||
| CVE-2024-45420 | Med | 0.28 | 4.3 | 0.00 | Nov 19, 2024 | Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2023-39205 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2023 | Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2023-39204 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2023 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2025-0146 | Low | 0.25 | 3.9 | 0.00 | Jan 30, 2025 | Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access. |
- risk 0.57cvss 8.8epss 0.01
Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.
- risk 0.57cvss 8.8epss 0.00
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
- risk 0.55cvss 8.5epss 0.01
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
- risk 0.48cvss 7.3epss 0.01
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
- risk 0.46cvss 7.1epss 0.01
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
- risk 0.46cvss 7.1epss 0.01
Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.
- risk 0.42cvss 6.5epss 0.01
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.42cvss 6.4epss 0.00
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
- risk 0.39cvss 6.0epss 0.00
Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.
- risk 0.35cvss 5.4epss 0.00
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
- risk 0.35cvss 5.4epss 0.01
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
- risk 0.35cvss 5.3epss 0.01
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.
- risk 0.34cvss 5.3epss 0.01
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
- risk 0.32cvss 4.9epss 0.01
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.
- risk 0.30cvss 4.6epss 0.00
Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access.
- risk 0.28cvss 4.3epss 0.00
Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.
- risk 0.28cvss 4.3epss 0.01
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
- risk 0.28cvss 4.3epss 0.01
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.25cvss 3.9epss 0.00
Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.
Page 1 of 2