Show filters
492 Total Results
Displaying 91-100 of 492
Sort by:
Attacker Value
Unknown
CVE-2022-28764
Disclosure Date: November 10, 2022 (last updated February 24, 2025)
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.
0
Attacker Value
Unknown
CVE-2022-28763
Disclosure Date: October 24, 2022 (last updated February 24, 2025)
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.
0
Attacker Value
Unknown
CVE-2022-28761
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.
0
Attacker Value
Unknown
CVE-2022-28762
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local malicious user could use this debugging port to connect to and control the Zoom Apps running in the Zoom client.
0
Attacker Value
Unknown
CVE-2022-28759
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
0
Attacker Value
Unknown
CVE-2022-28758
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
0
Attacker Value
Unknown
CVE-2022-28760
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
0
Attacker Value
Unknown
CVE-2022-28757
Disclosure Date: August 17, 2022 (last updated February 24, 2025)
The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.
0
Attacker Value
Unknown
CVE-2022-28750
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions older than 4.8.12.20211115, this vulnerability could also be leveraged to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-28754
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.
0