Vulnerabilities > Zoom > Zoom > 3.5.20913.0716

DATE CVE VULNERABILITY TITLE RISK
2023-08-08 CVE-2023-36535 Unspecified vulnerability in Zoom
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.
network
low complexity
zoom
6.5
2023-08-08 CVE-2023-39218 Unspecified vulnerability in Zoom
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.
network
low complexity
zoom
4.9
2023-06-13 CVE-2023-34114 Exposure of Resource to Wrong Sphere vulnerability in Zoom
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.
network
low complexity
zoom CWE-668
6.5
2023-06-13 CVE-2023-28600 Unspecified vulnerability in Zoom
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability.
network
low complexity
zoom
5.4
2023-06-13 CVE-2023-28599 Injection vulnerability in Zoom
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability.
network
low complexity
zoom CWE-74
4.3
2021-03-18 CVE-2021-28133 Information Exposure vulnerability in Zoom
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen.
network
zoom CWE-200
4.3
2019-07-12 CVE-2019-13567 OS Command Injection vulnerability in Zoom
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.
network
zoom CWE-78
6.8
2019-07-09 CVE-2019-13450 Missing Authorization vulnerability in multiple products
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active.
network
low complexity
ringcentral zoom CWE-862
6.5
2019-07-09 CVE-2019-13449 Improper Input Validation vulnerability in Zoom
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
network
low complexity
zoom CWE-20
6.5
2018-11-30 CVE-2018-15715 Improper Input Validation vulnerability in Zoom
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing.
network
low complexity
zoom CWE-20
7.5