VYPR

Zoom Client

by Zoom Video Communications, Inc.

CVEs (9)

  • CVE-2020-6109CriJun 8, 2020
    risk 0.64cvss 9.8epss 0.05

    An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An…

  • CVE-2018-15715CriNov 30, 2018
    risk 0.64cvss 9.8epss 0.03

    Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom…

  • CVE-2020-6110HigJun 8, 2020
    risk 0.58cvss 8.8epss 0.04

    An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution.…

  • CVE-2019-13567HigJul 12, 2019
    risk 0.58cvss 8.8epss 0.04

    The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute…

  • CVE-2019-13450MedJul 9, 2019
    risk 0.43cvss 6.5epss 0.04

    In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a…

  • CVE-2025-46789MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

  • CVE-2019-13449MedJul 9, 2019
    risk 0.42cvss 6.5epss 0.02

    In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.

  • CVE-2025-62483MedNov 13, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2025-30669MedNov 13, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.