cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2020-3604,https://securityvulnerability.io/vulnerability/CVE-2020-3604,Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities,Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.,Cisco,Cisco Webex Network Recording Player,7.8,HIGH,0.0012100000167265534,false,,false,false,true,2024-08-04T08:16:48.000Z,,false,false,,2020-11-06T19:15:00.000Z,0 CVE-2020-3603,https://securityvulnerability.io/vulnerability/CVE-2020-3603,Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities,Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.,Cisco,Cisco Webex Network Recording Player,7.8,HIGH,0.0012100000167265534,false,,false,false,true,2024-08-04T08:16:48.000Z,,false,false,,2020-11-06T19:15:00.000Z,0 CVE-2020-3573,https://securityvulnerability.io/vulnerability/CVE-2020-3573,Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities,Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.,Cisco,Cisco Webex Network Recording Player,7.8,HIGH,0.0008500000112690032,false,,false,false,true,2024-08-04T08:16:46.000Z,,false,false,,2020-11-06T19:15:00.000Z,0 CVE-2020-3321,https://securityvulnerability.io/vulnerability/CVE-2020-3321,Cisco Webex Network Recording Player and Cisco Webex Player Denial of Service Vulnerability,A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.,Cisco,"Cisco Webex Network Recording Player,Cisco Webex Player For Microsoft Windows",3.3,LOW,0.0005499999970197678,false,,false,false,false,,,false,false,,2020-06-03T00:00:00.000Z,0 CVE-2020-3319,https://securityvulnerability.io/vulnerability/CVE-2020-3319,Cisco Webex Network Recording Player and Cisco Webex Player Denial of Service Vulnerability,A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file. This vulnerability affects Cisco Webex Network Recording Player and Webex Player releases earlier than Release 3.0 MR3 Security Patch 2 and 4.0 MR3.,Cisco,"Cisco Webex Network Recording Player,Cisco Webex Player For Microsoft Windows",3.3,LOW,0.0005499999970197678,false,,false,false,false,,,false,false,,2020-06-03T00:00:00.000Z,0 CVE-2020-3322,https://securityvulnerability.io/vulnerability/CVE-2020-3322,Cisco Webex Network Recording Player and Cisco Webex Player Denial of Service Vulnerability,A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.,Cisco,"Cisco Webex Network Recording Player,Cisco Webex Player For Microsoft Windows",3.3,LOW,0.0005499999970197678,false,,false,false,false,,,false,false,,2020-06-03T00:00:00.000Z,0 CVE-2018-0380,https://securityvulnerability.io/vulnerability/CVE-2018-0380,,"Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could cause an affected player to crash, resulting in a denial of service (DoS) condition. The Cisco Webex players are applications that are used to play back Webex meetings that have been recorded by an online meeting attendee. The Webex Network Recording Player for .arf files can be automatically installed when the user accesses a recording that is hosted on a Webex server. The Webex Player for .wrf files can be downloaded manually. These vulnerabilities affect ARF and WRF recording players available from Cisco Webex Meetings Suite sites, Cisco Webex Meetings Online sites, and Cisco Webex Meetings Server. Cisco Bug IDs: CSCvh70253, CSCvh70268, CSCvh72272, CSCvh72281, CSCvh72285, CSCvi60477, CSCvi60485, CSCvi60490, CSCvi60520, CSCvi60529, CSCvi60533.",Cisco,Cisco Webex Network Recording Players Unknown,5.5,MEDIUM,0.0011699999449774623,false,,false,false,false,,,false,false,,2018-07-18T23:29:00.000Z,0 CVE-2018-0379,https://securityvulnerability.io/vulnerability/CVE-2018-0379,,"Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could allow arbitrary code execution on the system of a targeted user. These vulnerabilities affect ARF and WRF recording players available from Cisco Webex Meetings Suite sites, Cisco Webex Meetings Online sites, and Cisco Webex Meetings Server. Cisco Bug IDs: CSCvi02621, CSCvi02965, CSCvi63329, CSCvi63333, CSCvi63335, CSCvi63374, CSCvi63376, CSCvi63377, CSCvi63391, CSCvi63392, CSCvi63396, CSCvi63495, CSCvi63497, CSCvi63498, CSCvi82684, CSCvi82700, CSCvi82705, CSCvi82725, CSCvi82737, CSCvi82742, CSCvi82760, CSCvi82771, CSCvj51284, CSCvj51294.",Cisco,Cisco Webex Network Recording Players Unknown,7.8,HIGH,0.003370000049471855,false,,false,false,false,,,false,false,,2018-07-18T23:29:00.000Z,0 CVE-2018-0103,https://securityvulnerability.io/vulnerability/CVE-2018-0103,,"A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and persuading the user to follow the link or launch the file. Successful exploitation could allow the attacker to execute arbitrary code on the user's system. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, Cisco WebEx Meetings Server, and Cisco WebEx ARF players. Cisco Bug IDs: CSCvg78835, CSCvg78837, CSCvg78839.",Cisco,Cisco Webex Network Recording Player,7.8,HIGH,0.0018899999558925629,false,,false,false,false,,,false,false,,2018-01-04T06:00:00.000Z,0 CVE-2017-12360,https://securityvulnerability.io/vulnerability/CVE-2017-12360,,"A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file via email or URL and convincing the user to open the file. A successful exploit could cause an affected player to crash, resulting in a DoS condition. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, and Cisco WebEx WRF players. Cisco Bug IDs: CSCve30294, CSCve30301.",Cisco,Cisco Webex Network Recording Player,4.3,MEDIUM,0.0010000000474974513,false,,false,false,false,,,false,false,,2017-11-30T09:00:00.000Z,0 CVE-2017-12359,https://securityvulnerability.io/vulnerability/CVE-2017-12359,,"A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (.arf) files could allow an attacker to execute arbitrary code on a system. An attacker could exploit this vulnerability by providing a user with a malicious .arf file via email or URL and convincing the user to launch the file. Exploitation of this vulnerability could allow arbitrary code execution on the system of the targeted user. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, Cisco WebEx Meetings Server, and Cisco WebEx ARF players. Cisco Bug IDs: CSCve10729, CSCve10771, CSCve10779, CSCve11521, CSCve11543.",Cisco,Cisco Webex Network Recording Player,6.5,MEDIUM,0.0014900000533089042,false,,false,false,false,,,false,false,,2017-11-30T09:00:00.000Z,0 CVE-2017-6669,https://securityvulnerability.io/vulnerability/CVE-2017-6669,,"Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious ARF file via email or URL and convincing the user to launch the file. Exploitation of these vulnerabilities could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. The Cisco WebEx Network Recording Player is an application that is used to play back WebEx meeting recordings that have been recorded on the computer of an online meeting attendee. The player can be automatically installed when the user accesses a recording file that is hosted on a WebEx server. The following client builds are affected by this vulnerability: Cisco WebEx Business Suite (WBS29) client builds prior to T29.13.130, Cisco WebEx Business Suite (WBS30) client builds prior to T30.17, Cisco WebEx Business Suite (WBS31) client builds prior to T31.10. Cisco Bug IDs: CSCvc47758 CSCvc51227 CSCvc51242.",Cisco,Cisco Webex Network Recording Player,7.8,HIGH,0.0031500000040978193,false,,false,false,false,,,false,false,,2017-06-26T07:00:00.000Z,0