Show filters
231 Total Results
Displaying 71-80 of 231
Sort by:
Attacker Value
Unknown

CVE-2023-43582

Disclosure Date: November 15, 2023 (last updated September 19, 2024)
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
Attacker Value
Unknown

CVE-2023-39206

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-39205

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-39204

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-39203

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
Attacker Value
Unknown

CVE-2023-39199

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
Attacker Value
Unknown

CVE-2023-44981

Disclosure Date: October 11, 2023 (last updated February 14, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like 'eve@EXAMPLE.COM', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.
Attacker Value
Unknown

CVE-2023-41614

Disclosure Date: September 21, 2023 (last updated November 15, 2023)
A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.
Attacker Value
Unknown

CVE-2023-39215

Disclosure Date: September 12, 2023 (last updated September 27, 2024)
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-39208

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.