Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown
CVE-2021-26738
Disclosure Date: October 23, 2023 (last updated October 27, 2023)
Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.
0
Attacker Value
Unknown
CVE-2021-26737
Disclosure Date: October 23, 2023 (last updated October 27, 2023)
The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.
0
Attacker Value
Unknown
CVE-2021-26736
Disclosure Date: October 23, 2023 (last updated October 27, 2023)
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.
0
Attacker Value
Unknown
CVE-2021-26735
Disclosure Date: October 23, 2023 (last updated October 27, 2023)
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.
0
Attacker Value
Unknown
CVE-2021-26734
Disclosure Date: October 23, 2023 (last updated October 27, 2023)
Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context.
0
Attacker Value
Unknown
CVE-2023-28800
Disclosure Date: June 22, 2023 (last updated October 17, 2024)
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
0
Attacker Value
Unknown
CVE-2023-28799
Disclosure Date: June 22, 2023 (last updated October 17, 2024)
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
0
Attacker Value
Unknown
CVE-2021-34423
Disclosure Date: November 24, 2021 (last updated February 23, 2025)
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Ins…
0
Attacker Value
Unknown
CVE-2020-11632
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
0
Attacker Value
Unknown
CVE-2020-11634
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context.
0