Skip to content
Noroxi

Zoom records

236 published records for vendor zoom.

All records

236 records
  • Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password

    CriticalCVSS 10.0No exploitEPSS 4%

    zoom · model 5560 x3 ethernet adsl modemAug 6, 2004

  • The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell

    HighCVSS 8.8Proof of conceptEPSS 17%

    zoom · zoomDec 19, 2017

  • An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.

    CriticalCVSS 9.8No exploitEPSS 5%

    zoom · zoomJun 8, 2020

  • Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are v

    CriticalCVSS 9.8No exploitEPSS 3%

    zoom · zoomNov 30, 2018

  • Buffer overflow in Zoom client and other products

    CriticalCVSS 9.8No exploitEPSS 3%

    zoom · meetingsNov 24, 2021

  • The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m

    CriticalCVSS 9.8No exploitEPSS 3%

    zoom · meetingsSep 27, 2021

  • Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connector

    CriticalCVSS 9.8No exploitEPSS 2%

    zoom · meeting connectorAug 11, 2022

  • Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation

    CriticalCVSS 9.8No exploitEPSS 2%

    zoom · meeting software development kitFeb 13, 2024

  • The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-pr

    CriticalCVSS 9.8No exploitEPSS 2%

    zoom · meeting connectorSep 27, 2021

  • Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via n

    CriticalCVSS 9.8No exploitEPSS 2%

    zoom · zoomAug 8, 2023

  • Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate

    CriticalCVSS 9.8No exploitEPSS 1%

    zoom · virtual desktop infrastructureAug 8, 2023

  • Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv

    CriticalCVSS 9.8No exploitEPSS 1%

    zoom · zoomAug 8, 2023

  • CVE-2025-0147
    39Monitor

    Zoom Workplace App for Linux - Type Confusion

    CriticalCVSS 9.8No exploitEPSS 1%

    zoom · meeting software development kitJan 30, 2025

  • Zoom Workplace VDI Plugin for Windows - Improper Input Validation

    CriticalCVSS 9.8No exploitEPSS 1%

    zoom · workplace desktopJul 16, 2026

  • External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to co

    CriticalCVSS 9.8No exploitEPSS 0%

    zoom · workplace desktopMar 11, 2026

  • Zoom Workplace for Android - Improper Authorization Handling

    CriticalCVSS 9.8No exploitEPSS 0%

    zoom · meeting software development kitNov 13, 2025

  • Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo

    CriticalCVSS 9.8No exploitEPSS 0%

    zoom · workplaceJun 12, 2026

  • Zoom Workplace Clients - Inefficient Regular Expression Complexity

    CriticalCVSS 9.8No exploitEPSS 0%

    zoom · meeting software development kitNov 13, 2025

  • Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execut

    HighCVSS 8.8Proof of conceptEPSS 10%

    zoom · zoomDec 19, 2017

  • Improper URL parsing in Zoom Clients

    CriticalCVSS 9.6No exploitEPSS 1%

    zoom · meetingsOct 31, 2022

  • Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user inter

    HighCVSS 8.8No exploitEPSS 6%

    zoom · chatApr 9, 2021

  • Improperly constrained session cookies in Zoom Client for Meetings

    CriticalCVSS 9.1No exploitEPSS 3%

    zoom · meetingsMay 18, 2022

  • CVE-2020-6110
    36Monitor

    An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code sn

    HighCVSS 8.8No exploitEPSS 4%

    zoom · zoomJun 8, 2020

  • The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.

    HighCVSS 8.8No exploitEPSS 4%

    zoom · zoomJul 12, 2019

  • Zoom Workplace for Linux - Improper Certificate Validation

    CriticalCVSS 9.1No exploitEPSS 0%

    zoom · workplace desktopJul 10, 2025