Записи Zoom
236 опубликованных записей вендора zoom.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation16
- CWE-426 Untrusted Search Path13
- CWE-347 Improper Verification of Cryptographic Signature12
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition10
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')8
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
236 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2004-0680Эксплойта нет | Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password zoom · model 5560 x3 ethernet adsl modem | Критическая10,0 | — | 3,6 % | 6 авг. 2004 г. |
40В плане | CVE-2017-15049Proof of concept | The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell zoom · zoom · CWE-78 | Высокая8,8 | — | 17,0 % | 19 дек. 2017 г. |
40В плане | CVE-2020-6109Эксплойта нет | An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.zoom · zoom · CWE-22 | Критическая9,8 | — | 4,7 % | 8 июн. 2020 г. |
40В плане | CVE-2018-15715Эксплойта нет | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vzoom · zoom · CWE-290 | Критическая9,8 | — | 3,5 % | 30 нояб. 2018 г. |
40В плане | CVE-2021-34423Эксплойта нет | Buffer overflow in Zoom client and other productszoom · meetings · CWE-120 | Критическая9,8 | — | 3,3 % | 24 нояб. 2021 г. |
40В плане | CVE-2021-33907Эксплойта нет | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .mzoom · meetings · CWE-295 | Критическая9,8 | — | 3,0 % | 27 сент. 2021 г. |
40В плане | CVE-2022-28750Эксплойта нет | Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connectorzoom · meeting connector · CWE-121 | Критическая9,8 | — | 2,0 % | 11 авг. 2022 г. |
40В плане | CVE-2024-24691Эксплойта нет | Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validationzoom · meeting software development kit · CWE-176 | Критическая9,8 | — | 1,7 % | 13 февр. 2024 г. |
39Наблюдать | CVE-2021-34416Эксплойта нет | The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-przoom · meeting connector · CWE-20 | Критическая9,8 | — | 1,6 % | 27 сент. 2021 г. |
39Наблюдать | CVE-2023-36534Эксплойта нет | Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via nzoom · zoom · CWE-22 | Критическая9,8 | — | 1,6 % | 8 авг. 2023 г. |
39Наблюдать | CVE-2023-39213Эксплойта нет | Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticatezoom · virtual desktop infrastructure · CWE-176 | Критическая9,8 | — | 1,4 % | 8 авг. 2023 г. |
39Наблюдать | CVE-2023-39216Эксплойта нет | Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privzoom · zoom · CWE-80 | Критическая9,8 | — | 1,2 % | 8 авг. 2023 г. |
39Наблюдать | CVE-2025-0147Эксплойта нет | Zoom Workplace App for Linux - Type Confusionzoom · meeting software development kit · CWE-843 | Критическая9,8 | — | 0,6 % | 30 янв. 2025 г. |
39Наблюдать | CVE-2026-53412Эксплойта нет | Zoom Workplace VDI Plugin for Windows - Improper Input Validationzoom · workplace desktop · CWE-20 | Критическая9,8 | — | 0,5 % | 16 июл. 2026 г. |
39Наблюдать | CVE-2026-30903Эксплойта нет | External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to cozoom · workplace desktop · CWE-73 | Критическая9,8 | — | 0,4 % | 11 мар. 2026 г. |
39Наблюдать | CVE-2025-64741Эксплойта нет | Zoom Workplace for Android - Improper Authorization Handlingzoom · meeting software development kit · CWE-74 | Критическая9,8 | — | 0,4 % | 13 нояб. 2025 г. |
39Наблюдать | CVE-2026-53407Эксплойта нет | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allozoom · workplace · CWE-939 | Критическая9,8 | — | 0,4 % | 12 июн. 2026 г. |
39Наблюдать | CVE-2025-62484Эксплойта нет | Zoom Workplace Clients - Inefficient Regular Expression Complexityzoom · meeting software development kit · CWE-1333 | Критическая9,8 | — | 0,3 % | 13 нояб. 2025 г. |
38Наблюдать | CVE-2017-15048Proof of concept | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to executzoom · zoom · CWE-119 | Высокая8,8 | — | 10,2 % | 19 дек. 2017 г. |
38Наблюдать | CVE-2022-28763Эксплойта нет | Improper URL parsing in Zoom Clientszoom · meetings · CWE-20 | Критическая9,6 | — | 1,2 % | 31 окт. 2022 г. |
37Наблюдать | CVE-2021-30480Эксплойта нет | Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interzoom · chat | Высокая8,8 | — | 5,8 % | 9 апр. 2021 г. |
37Наблюдать | CVE-2022-22785Эксплойта нет | Improperly constrained session cookies in Zoom Client for Meetingszoom · meetings · CWE-565 | Критическая9,1 | — | 3,5 % | 18 мая 2022 г. |
36Наблюдать | CVE-2020-6110Эксплойта нет | An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snzoom · zoom · CWE-22 | Высокая8,8 | — | 4,3 % | 8 июн. 2020 г. |
36Наблюдать | CVE-2019-13567Эксплойта нет | The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.zoom · zoom · CWE-78 | Высокая8,8 | — | 3,8 % | 12 июл. 2019 г. |
36Наблюдать | CVE-2025-46788Эксплойта нет | Zoom Workplace for Linux - Improper Certificate Validationzoom · workplace desktop · CWE-295 | Критическая9,1 | — | 0,2 % | 10 июл. 2025 г. |
- CVE-2004-068041В плане
Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %zoom · model 5560 x3 ethernet adsl modem6 авг. 2004 г.
- CVE-2017-1504940В плане
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %zoom · zoom19 дек. 2017 г.
- CVE-2020-610940В плане
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %zoom · zoom8 июн. 2020 г.
- CVE-2018-1571540В плане
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are v
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zoom · zoom30 нояб. 2018 г.
- CVE-2021-3442340В плане
Buffer overflow in Zoom client and other products
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zoom · meetings24 нояб. 2021 г.
- CVE-2021-3390740В плане
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zoom · meetings27 сент. 2021 г.
- CVE-2022-2875040В плане
Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connector
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zoom · meeting connector11 авг. 2022 г.
- CVE-2024-2469140В плане
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zoom · meeting software development kit13 февр. 2024 г.
- CVE-2021-3441639Наблюдать
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-pr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zoom · meeting connector27 сент. 2021 г.
- CVE-2023-3653439Наблюдать
Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via n
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zoom · zoom8 авг. 2023 г.
- CVE-2023-3921339Наблюдать
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zoom · virtual desktop infrastructure8 авг. 2023 г.
- CVE-2023-3921639Наблюдать
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zoom · zoom8 авг. 2023 г.
- CVE-2025-014739Наблюдать
Zoom Workplace App for Linux - Type Confusion
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zoom · meeting software development kit30 янв. 2025 г.
- CVE-2026-5341239Наблюдать
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zoom · workplace desktop16 июл. 2026 г.
- CVE-2026-3090339Наблюдать
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to co
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %zoom · workplace desktop11 мар. 2026 г.
- CVE-2025-6474139Наблюдать
Zoom Workplace for Android - Improper Authorization Handling
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %zoom · meeting software development kit13 нояб. 2025 г.
- CVE-2026-5340739Наблюдать
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %zoom · workplace12 июн. 2026 г.
- CVE-2025-6248439Наблюдать
Zoom Workplace Clients - Inefficient Regular Expression Complexity
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %zoom · meeting software development kit13 нояб. 2025 г.
- CVE-2017-1504838Наблюдать
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execut
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %zoom · zoom19 дек. 2017 г.
- CVE-2022-2876338Наблюдать
Improper URL parsing in Zoom Clients
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %zoom · meetings31 окт. 2022 г.
- CVE-2021-3048037Наблюдать
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user inter
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %zoom · chat9 апр. 2021 г.
- CVE-2022-2278537Наблюдать
Improperly constrained session cookies in Zoom Client for Meetings
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %zoom · meetings18 мая 2022 г.
- CVE-2020-611036Наблюдать
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code sn
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %zoom · zoom8 июн. 2020 г.
- CVE-2019-1356736Наблюдать
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %zoom · zoom12 июл. 2019 г.
- CVE-2025-4678836Наблюдать
Zoom Workplace for Linux - Improper Certificate Validation
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %zoom · workplace desktop10 июл. 2025 г.