Vulnerabilities > Zoom > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-11 CVE-2021-34419 Injection vulnerability in Zoom Client for Meetings
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing.
network
low complexity
zoom CWE-74
5.3
2021-03-18 CVE-2021-28133 Information Exposure vulnerability in Zoom
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen.
network
low complexity
zoom CWE-200
4.3
2019-07-09 CVE-2019-13450 Missing Authorization vulnerability in multiple products
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active.
network
low complexity
ringcentral zoom CWE-862
6.5
2019-07-09 CVE-2019-13449 Improper Input Validation vulnerability in Zoom
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
network
low complexity
zoom CWE-20
6.5