İçeriğe atla
Noroxi

bigbluebutton kayıtları

bigbluebutton üreticisine ait 55 yayımlanmış kayıt.

Tüm kayıtlar

55 kayıt
  • CVE-2020-12443
    40Planlayın

    BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename

    KritikCVSS 9,8İstismar yokEPSS %4

    bigbluebutton · bigbluebutton28 Nis 2020

  • CVE-2020-27602
    39İzleyin

    BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

    KritikCVSS 9,8İstismar yokEPSS %1

    bigbluebutton · bigbluebutton28 Eyl 2022

  • CVE-2020-27605
    39İzleyin

    BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related t

    KritikCVSS 9,8İstismar yokEPSS %1

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2020-26163
    35İzleyin

    BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows

    YüksekCVSS 8,8İstismar yokEPSS %2

    bigbluebutton · greenlight30 Eyl 2020

  • CVE-2023-42803
    35İzleyin

    BigBlueButton Unrestricted File Upload vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    bigbluebutton · bigbluebutton30 Eki 2023

  • CVE-2020-27613
    33İzleyin

    The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to

    YüksekCVSS 8,4İstismar yokEPSS %0

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2020-12112
    32İzleyin

    BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    bigbluebutton · bigbluebutton23 Nis 2020

  • CVE-2026-27466
    32İzleyin

    BigBlueButton: Exposed ClamAV port enables Denial of Service

    YüksekCVSS 8,2İstismar yokEPSS %1

    bigbluebutton · bigbluebutton21 Şub 2026

  • CVE-2020-27603
    31İzleyin

    BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2022-29169
    30İzleyin

    ReDoS on endpoint html5client/useragent in BigBlueButton

    YüksekCVSS 7,5İstismar yokEPSS %2

    bigbluebutton · bigbluebutton1 Haz 2022

  • CVE-2020-29043
    30İzleyin

    An issue was discovered in BigBlueButton through 2.2.29.

    YüksekCVSS 7,5İstismar yokEPSS %1

    bigbluebutton · bigbluebutton26 Kas 2020

  • CVE-2020-27610
    30İzleyin

    The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not

    YüksekCVSS 7,5İstismar yokEPSS %1

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2022-23488
    30İzleyin

    BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data

    YüksekCVSS 7,5İstismar yokEPSS %1

    bigbluebutton · bigbluebutton16 Ara 2022

  • CVE-2025-61601
    30İzleyin

    BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation

    YüksekCVSS 7,5İstismar yokEPSS %0

    bigbluebutton · bigbluebutton9 Eki 2025

  • CVE-2025-61602
    30İzleyin

    BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId

    YüksekCVSS 7,5İstismar yokEPSS %0

    bigbluebutton · bigbluebutton9 Eki 2025

  • CVE-2020-25820
    29İzleyin

    BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document th

    OrtaCVSS 6,5Kavram kanıtıEPSS %10

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2020-27611
    29İzleyin

    BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.

    YüksekCVSS 7,3İstismar yokEPSS %1

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2020-27604
    26İzleyin

    BigBlueButton before 2.3 does not implement LibreOffice sandboxing.

    OrtaCVSS 6,5İstismar yokEPSS %1

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2022-29232
    26İzleyin

    Exposure of messages in BigBlueButton public chats

    OrtaCVSS 6,5İstismar yokEPSS %1

    bigbluebutton · bigbluebutton1 Haz 2022

  • CVE-2020-27607
    26İzleyin

    In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data fro

    OrtaCVSS 6,5İstismar yokEPSS %1

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2023-33176
    26İzleyin

    Blind SSRF When Uploading Presentation in BigBlueButton

    OrtaCVSS 6,5İstismar yokEPSS %0

    bigbluebutton · bigbluebutton26 Haz 2023

  • CVE-2020-12113
    24İzleyin

    BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

    OrtaCVSS 6,1İstismar yokEPSS %1

    bigbluebutton · bigbluebutton23 Nis 2020

  • CVE-2021-4143
    24İzleyin

    Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton

    OrtaCVSS 6,1İstismar yokEPSS %1

    bigbluebutton · bigbluebutton19 Oca 2022

  • CVE-2020-27608
    24İzleyin

    In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as

    OrtaCVSS 6,1İstismar yokEPSS %1

    bigbluebutton · bigbluebutton21 Eki 2020

  • CVE-2020-27642
    24İzleyin

    A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.

    OrtaCVSS 6,1İstismar yokEPSS %1

    bigbluebutton · greenlight22 Eki 2020