cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2023-43583,https://securityvulnerability.io/vulnerability/CVE-2023-43583,Cryptographic Issues in Zoom Mobile App for Android and iOS,Cryptographic flaws in the Zoom Mobile App for Android and iOS and the corresponding SDKs prior to version 5.16.0 may expose sensitive information to a privileged user via network access. This vulnerability highlights the importance of implementing robust encryption protocols to protect user data from unauthorized access. Users of affected versions should prioritize upgrading their applications to the latest version to mitigate potential risks.,"Zoom Video Communications, Inc.","Zoom Mobile App For Android, Zoom Mobile App For iOS And Zoom Sdk",4.9,MEDIUM,0.0006399999838322401,false,false,false,false,,false,false,2023-12-13T23:15:00.000Z,0 CVE-2023-28599,https://securityvulnerability.io/vulnerability/CVE-2023-28599,,Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.,"Zoom Video Communications, Inc.","Zoom For Android,Zoom For iOS,Zoom For Linux,Zoom For Mac OS,Zoom For Windows",4.3,MEDIUM,0.0005600000149570405,false,false,false,false,,false,false,2023-06-13T17:15:00.000Z,0 CVE-2023-28597,https://securityvulnerability.io/vulnerability/CVE-2023-28597,Improper trust boundary implementation for SMB in Zoom Clients,"Zoom clients earlier than version 5.13.5 are impacted by a vulnerability related to improper trust boundary implementation. When users save local recordings to an SMB location and later access them via a link from the Zoom web portal, an attacker on an adjacent network may exploit this weakness. By establishing a malicious SMB server, the attacker can intercept client requests and inadvertently execute harmful executables on the client's device. This scenario poses significant risks, including unauthorized access to user data and the potential for remote code execution, highlighting the importance of maintaining up-to-date software for security.",Zoom,"Zoom (for Android, iOS, Linux, macOS, and Windows),Zoom Rooms (for Android, iOS, Linux, macOS, and Windows),Zoom VDI for Windows",7.5,HIGH,0.0010100000072270632,false,false,false,false,,false,false,2023-03-27T00:00:00.000Z,0 CVE-2023-22882,https://securityvulnerability.io/vulnerability/CVE-2023-22882,Denial of Service in Zoom Clients,"Zoom clients prior to version 5.13.5 are susceptible to a STUN parsing vulnerability. An attacker can exploit this flaw by sending specially crafted UDP packets to a vulnerable Zoom client, which may lead to the application crashing and resulting in a denial of service. It's crucial for users of Zoom to update their clients to the latest version to avoid potential disruptions caused by this vulnerability.",Zoom,"Zoom (for Android, iOS, Linux, macOS, and Windows) clients before version 5.13.5",7.5,HIGH,0.000859999970998615,false,false,false,false,,false,false,2023-03-16T00:00:00.000Z,0 CVE-2023-22881,https://securityvulnerability.io/vulnerability/CVE-2023-22881,Denial of Service in Zoom Clients,"A security flaw in Zoom clients prior to version 5.13.5 allows remote attackers to exploit a STUN parsing vulnerability. By sending specially crafted UDP packets to a vulnerable client, an attacker can trigger a crash, resulting in a denial of service. This vulnerability emphasizes the need for users to keep their software updated to protect against unforeseen attacks.",Zoom,"Zoom (for Android, iOS, Linux, macOS, and Windows) clients before version 5.13.5",7.5,HIGH,0.000859999970998615,false,false,false,false,,false,false,2023-03-16T00:00:00.000Z,0 CVE-2022-36928,https://securityvulnerability.io/vulnerability/CVE-2022-36928,Path Traversal in Zoom for Android Clients,Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.,Zoom,Zoom For Android,6.1,MEDIUM,0.0006099999882280827,false,false,false,false,,false,false,2023-01-09T00:00:00.000Z,0 CVE-2022-28764,https://securityvulnerability.io/vulnerability/CVE-2022-28764,Local information exposure in Zoom Clients,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Vdi Windows Meeting Clients,Zoom Rooms For Conference Room (for Android, iOS, Linux, Mac OS, And Windows)",3.3,LOW,0.0004199999966658652,false,false,false,false,,false,false,2022-11-14T21:15:00.000Z,0 CVE-2022-28763,https://securityvulnerability.io/vulnerability/CVE-2022-28763,Improper URL parsing in Zoom Clients,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Vdi Windows Meeting Clients,Zoom Rooms For Conference Room (for Android, iOS, Linux, Mac OS, And Windows)",8.8,HIGH,0.001970000099390745,false,false,false,false,,false,false,2022-10-31T20:15:00.000Z,0 CVE-2022-28755,https://securityvulnerability.io/vulnerability/CVE-2022-28755,Improper URL parsing in Zoom Clients,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Vdi Windows Meeting Clients",9.6,CRITICAL,0.001120000029914081,false,false,false,false,,false,false,2022-08-11T15:15:00.000Z,0 CVE-2022-22787,https://securityvulnerability.io/vulnerability/CVE-2022-22787,Insufficient hostname validation during Clusterswitch message in Zoom Client for Meetings,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting users client to connect to a malicious server when attempting to use Zoom services.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",5.9,MEDIUM,0.0013000000035390258,false,false,false,false,,false,false,2022-05-18T17:15:00.000Z,0 CVE-2022-22785,https://securityvulnerability.io/vulnerability/CVE-2022-22785,Improperly constrained session cookies in Zoom Client for Meetings,"The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",5.9,MEDIUM,0.0015200000489130616,false,false,false,false,,false,false,2022-05-18T16:15:00.000Z,0 CVE-2022-22784,https://securityvulnerability.io/vulnerability/CVE-2022-22784,Improper XML Parsing in Zoom Client for Meetings,"The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving users client perform a variety of actions.This issue could be used in a more sophisticated attack to forge XMPP messages from the server.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",8.1,HIGH,0.0006500000017695129,false,false,false,false,,false,false,2022-05-18T16:15:00.000Z,0 CVE-2022-22780,https://securityvulnerability.io/vulnerability/CVE-2022-22780,Zoom Chat Susceptible to Zip Bombing,"The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",4.7,MEDIUM,0.0009699999936856329,false,false,false,false,,false,false,2022-02-09T23:15:00.000Z,0 CVE-2021-34425,https://securityvulnerability.io/vulnerability/CVE-2021-34425,Server Side Request Forgery in Zoom Client for Meetings chat,"The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s ""link preview"" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s ""link preview"" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",4.7,MEDIUM,0.0007800000021234155,false,false,false,false,,false,false,2021-12-14T00:00:00.000Z,0 CVE-2021-34423,https://securityvulnerability.io/vulnerability/CVE-2021-34423,Buffer overflow in Zoom client and other products,"A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom On-Premise Meeting Connector Controller before version 4.8.12.20211115, Zoom On-Premise Meeting Connector MMR before version 4.8.12.20211115, Zoom On-Premise Recording Connector before version 5.1.0.65.20211116, Zoom On-Premise Virtual Room Connector before version 4.4.7266.20211117, Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64. This can potentially allow a malicious actor to crash the service or application, or leverage this vulnerability to execute arbitrary code.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Client For Meetings For Blackberry (for Android And iOS),Zoom Client For Meetings For Intune (for Android And iOS),Zoom Client For Meetings For Chrome Os,Zoom Rooms For Conference Room (for Android, Androidbali, Mac OS, And Windows),Controllers For Zoom Rooms (for Android, iOS, And Windows),Zoom Vdi Windows Meeting Client,Zoom Vdi Azure Virtual Desktop Plugins (for Windows X86 Or X64, Igel X64, Ubuntu X64, HP Thinpro Os X64),Zoom Vdi Citrix Plugins (for Windows X86 Or X64, Mac Universal Installer & Uninstaller, Igel X64, Elux Rp6 X64, HP Thinpro Os X64, Ubuntu X64, Centos X 64, Dell Thinos),Zoom Vdi Vmware Plugins (for Windows X86 Or X64, Mac Universal Installer & Uninstaller, Igel X64, Elux Rp6 X64, HP Thinpro Os X64, Ubuntu X64, Centos X 64, Dell Thinos),Zoom Meeting Sdk For Android,Zoom Meeting Sdk For iOS,Zoom Meeting Sdk For Mac OS,Zoom Meeting Sdk For Windows,Zoom Video Sdk (for Android, iOS, Mac OS, And Windows),Zoom On-premise Meeting Connector Controller,Zoom On-premise Meeting Connector Mmr,Zoom On-premise Recording Connector,Zoom On-premise Virtual Room Connector,Zoom On-premise Virtual Room Connector Load Balancer,Zoom Hybrid Zproxy,Zoom Hybrid Mmr",7.3,HIGH,0.005229999776929617,false,false,false,false,,false,false,2021-11-24T00:00:00.000Z,0 CVE-2021-34424,https://securityvulnerability.io/vulnerability/CVE-2021-34424,Process memory exposure in Zoom Client and other products,"A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom on-premise Meeting Connector before version 4.8.12.20211115, Zoom on-premise Meeting Connector MMR before version 4.8.12.20211115, Zoom on-premise Recording Connector before version 5.1.0.65.20211116, Zoom on-premise Virtual Room Connector before version 4.4.7266.20211117, Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64 which potentially allowed for the exposure of the state of process memory. This issue could be used to potentially gain insight into arbitrary areas of the product's memory.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Client For Meetings For Blackberry (for Android And iOS),Zoom Client For Meetings For Intune (for Android And iOS),Zoom Client For Meetings For Chrome Os,Zoom Rooms For Conference Room (for Android, Androidbali, Mac OS, And Windows),Controllers For Zoom Rooms (for Android, iOS, And Windows),Zoom Vdi Windows Meeting Client,Zoom Vdi Azure Virtual Desktop Plugins (for Windows X86 Or X64, Igel X64, Ubuntu X64, HP Thinpro Os X64),Zoom Vdi Citrix Plugins (for Windows X86 Or X64, Mac Universal Installer & Uninstaller, Igel X64, Elux Rp6 X64, HP Thinpro Os X64, Ubuntu X64, Centos X 64, Dell Thinos),Zoom Vdi Vmware Plugins (for Windows X86 Or X64, Mac Universal Installer & Uninstaller, Igel X64, Elux Rp6 X64, HP Thinpro Os X64, Ubuntu X64, Centos X 64, Dell Thinos),Zoom Meeting Sdk For Android,Zoom Meeting Sdk For iOS,Zoom Meeting Sdk For Mac OS,Zoom Meeting Sdk For Windows,Zoom Video Sdk (for Android, iOS, Mac OS, And Windows),Zoom On-premise Meeting Connector,Zoom On-premise Meeting Connector Mmr,Zoom On-premise Recording Connector,Zoom On-premise Virtual Room Connector,Zoom On-premise Virtual Room Connector Load Balancer,Zoom Hybrid Zproxy,Zoom Hybrid Mmr",5.3,MEDIUM,0.001769999973475933,false,false,false,false,,false,false,2021-11-24T00:00:00.000Z,0