Vulnerabilities > Zoom > Meetings > 5.8.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-15 | CVE-2023-43582 | Improper Authentication vulnerability in Zoom products Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. | 8.8 |
2023-11-15 | CVE-2023-43588 | Unspecified vulnerability in Zoom Meetings Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. | 6.5 |
2023-11-14 | CVE-2023-39199 | Unspecified vulnerability in Zoom products Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access. | 6.5 |
2023-11-14 | CVE-2023-39204 | Classic Buffer Overflow vulnerability in Zoom products Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. | 7.5 |
2023-11-14 | CVE-2023-39205 | Improper Check for Unusual or Exceptional Conditions vulnerability in Zoom products Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. | 6.5 |
2023-11-14 | CVE-2023-39206 | Classic Buffer Overflow vulnerability in Zoom products Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. | 7.5 |
2022-11-14 | CVE-2022-28764 | Incomplete Cleanup vulnerability in Zoom Meetings, Rooms and VDI Windows Meeting Clients The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. | 3.3 |
2022-10-31 | CVE-2022-28763 | Open Redirect vulnerability in Zoom Meetings and Virtual Desktop Infrastructure The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. | 9.6 |
2022-05-18 | CVE-2022-22787 | Improper Certificate Validation vulnerability in Zoom Meetings The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. | 7.5 |
2022-05-18 | CVE-2022-22784 | XML Injection (aka Blind XPath Injection) vulnerability in Zoom Meetings The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. | 8.1 |