Vulnerabilities > Cisco > Jabber > 12.6.2

DATE CVE VULNERABILITY TITLE RISK
2023-09-15 CVE-2022-20917 Unspecified vulnerability in Cisco Jabber
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP messages within requests that are sent to the Cisco Jabber client software.
network
low complexity
cisco
4.3
2021-03-24 CVE-2021-1418 Improper Null Termination vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-170
6.5
2021-03-24 CVE-2021-1471 Improper Certificate Validation vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
high complexity
cisco CWE-295
5.6
2021-01-07 CVE-2020-26085 OS Command Injection vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information.
network
low complexity
cisco CWE-78
critical
9.9
2020-09-04 CVE-2020-3537 Information Exposure vulnerability in Cisco Jabber
A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information.
network
low complexity
cisco CWE-200
5.7
2020-09-04 CVE-2020-3498 Improper Input Validation vulnerability in Cisco Jabber
A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information.
network
low complexity
cisco CWE-20
6.5
2020-09-04 CVE-2020-3495 Improper Input Validation vulnerability in Cisco Jabber
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code.
network
low complexity
cisco CWE-20
8.8
2020-09-04 CVE-2020-3430 OS Command Injection vulnerability in Cisco Jabber
A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands.
network
low complexity
cisco CWE-78
8.8