Show filters
3,556 Total Results
Displaying 191-200 of 3,556
Sort by:
Attacker Value
Unknown

CVE-2023-43582

Disclosure Date: November 15, 2023 (last updated February 25, 2025)
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
Attacker Value
Unknown

CVE-2023-39206

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-39205

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-39204

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-39203

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
Attacker Value
Unknown

CVE-2023-39202

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.
Attacker Value
Unknown

CVE-2023-39199

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
Attacker Value
Unknown

CVE-2023-4769

Disclosure Date: November 03, 2023 (last updated February 25, 2025)
A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.
Attacker Value
Unknown

CVE-2023-4768

Disclosure Date: November 03, 2023 (last updated February 25, 2025)
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
Attacker Value
Unknown

CVE-2023-4767

Disclosure Date: November 03, 2023 (last updated February 25, 2025)
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.