Loading HuntDB...

CVE-2024-27244

MEDIUM

Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

Published May 15, 2024

CVE-2024-27243

MEDIUM

Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.

Published May 15, 2024

CVE-2024-27242

MEDIUM

Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.

Published Apr 09, 2024

CVE-2024-27247

MEDIUM

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

Published Apr 09, 2024

CVE-2024-24694

MEDIUM

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.

Published Apr 09, 2024

CVE-2024-24693

HIGH

Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

Published Mar 13, 2024

CVE-2024-24692

MEDIUM

Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

Published Mar 13, 2024

CVE-2024-24691

CRITICAL

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

Published Feb 14, 2024

CVE-2024-24690

MEDIUM

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

Published Feb 14, 2024

CVE-2024-24699

MEDIUM

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

Published Feb 13, 2024

CVE-2024-24698

MEDIUM

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

Published Feb 13, 2024

CVE-2024-24697

HIGH

Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

Published Feb 13, 2024

CVE-2024-24696

MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

Published Feb 13, 2024

CVE-2024-24695

MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

Published Feb 13, 2024

CVE-2023-49647

HIGH

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

Published Jan 12, 2024

CVE-2023-49646

MEDIUM

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

Published Dec 13, 2023

CVE-2023-43586

HIGH

Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.

Published Dec 13, 2023

CVE-2023-43585

HIGH

Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.

Published Dec 13, 2023

CVE-2023-43583

MEDIUM

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.

Published Dec 13, 2023

CVE-2023-43591

HIGH

Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

Published Nov 14, 2023

CVE-2023-43590

HIGH

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

Published Nov 14, 2023

CVE-2023-43582

MEDIUM

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

Published Nov 14, 2023

CVE-2023-43588

LOW

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.

Published Nov 14, 2023

CVE-2023-39199

MEDIUM

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

Published Nov 14, 2023

CVE-2023-39206

LOW

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

Published Nov 14, 2023

CVE-2023-39205

MEDIUM

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

Published Nov 14, 2023

CVE-2023-39204

MEDIUM

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

Published Nov 14, 2023

CVE-2023-39203

MEDIUM

Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

Published Nov 14, 2023

CVE-2023-39202

LOW

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

Published Nov 14, 2023

CVE-2023-39201

HIGH

Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access.

Published Sep 12, 2023

CVE-2023-39208

MEDIUM

Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.

Published Sep 12, 2023

CVE-2023-39215

HIGH

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

Published Sep 12, 2023

CVE-2023-39209

MEDIUM

Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

Published Aug 08, 2023

CVE-2023-39214

HIGH

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

Published Aug 08, 2023

CVE-2023-39213

CRITICAL

Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

Published Aug 08, 2023

CVE-2023-39212

HIGH

Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

Published Aug 08, 2023

CVE-2023-39211

HIGH

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

Published Aug 08, 2023

CVE-2023-39210

MEDIUM

Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.

Published Aug 08, 2023

CVE-2023-39218

MEDIUM

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

Published Aug 08, 2023

CVE-2023-39217

MEDIUM

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.

Published Aug 08, 2023

CVE-2023-39216

CRITICAL

Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

Published Aug 08, 2023

CVE-2023-36535

HIGH

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

Published Aug 08, 2023

CVE-2023-36534

CRITICAL

Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

Published Aug 08, 2023

CVE-2023-36533

HIGH

Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.

Published Aug 08, 2023

CVE-2023-36532

MEDIUM

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

Published Aug 08, 2023

CVE-2023-36541

HIGH

Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.

Published Aug 08, 2023

CVE-2023-36540

HIGH

Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

Published Aug 08, 2023

CVE-2023-36538

HIGH

Improper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

Published Jul 11, 2023

CVE-2023-36537

HIGH

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

Published Jul 11, 2023

CVE-2023-36536

HIGH

Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

Published Jul 11, 2023