Vulnerabilities > Zoom > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-06-08 CVE-2020-6110 Path Traversal vulnerability in Zoom 4.6.10
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets.
network
zoom CWE-22
6.8
2020-04-03 CVE-2020-11500 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Zoom Meetings 4.6.8
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption.
network
low complexity
zoom CWE-327
5.0
2019-07-12 CVE-2019-13567 OS Command Injection vulnerability in Zoom
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.
network
zoom CWE-78
6.8
2019-07-09 CVE-2019-13450 Missing Authorization vulnerability in multiple products
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active.
network
low complexity
ringcentral zoom CWE-862
6.5
2019-07-09 CVE-2019-13449 Improper Input Validation vulnerability in Zoom
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
network
low complexity
zoom CWE-20
6.5
2017-12-19 CVE-2017-15048 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Zoom
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
network
zoom CWE-119
6.8
2014-09-09 CVE-2014-5811 Cryptographic Issues vulnerability in Zoom Cloud Meetings @7F060008
The ZOOM Cloud Meetings (aka us.zoom.videomeetings) application @7F060008 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
5.4