Vulnerabilities > Zoom

DATE CVE VULNERABILITY TITLE RISK
2018-11-30 CVE-2018-15715 Improper Input Validation vulnerability in Zoom
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing.
network
low complexity
zoom CWE-20
critical
9.8
2017-12-19 CVE-2017-15049 OS Command Injection vulnerability in Zoom
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
network
low complexity
zoom CWE-78
8.8
2017-12-19 CVE-2017-15048 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Zoom
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
network
low complexity
zoom CWE-119
8.8