VYPR

Jabber for Windows

by Cisco Systems, Inc.

CVEs (8)

  • CVE-2020-3495CriSep 4, 2020
    risk 0.69cvss 9.9epss 0.62

    A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible…

  • CVE-2021-1417CriMar 24, 2021
    risk 0.64cvss 9.9epss 0.01

    Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept…

  • CVE-2020-3430HigSep 4, 2020
    risk 0.58cvss 8.8epss 0.04

    A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper handling of input to the application protocol handlers. An attacker could…

  • CVE-2019-1855HigJul 4, 2019
    risk 0.48cvss 7.3epss 0.02

    A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading attack. To exploit this vulnerability, the attacker would need to have valid credentials on the…

  • CVE-2020-3537MedSep 4, 2020
    risk 0.37cvss 5.7epss 0.01

    A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially…

  • CVE-2017-12284MedOct 19, 2017
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input- and…

  • CVE-2017-12361MedNov 30, 2017
    risk 0.26cvss 4.0epss 0.00

    A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information to conduct additional attacks. The vulnerability is due to…

  • CVE-2013-3393Jun 26, 2013
    risk 0.00cvss epss 0.01

    The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117.