This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Zoom First view 2023-08-08
Product Video Software Development Kit Last view 2024-01-12
Version * Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software linux  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:zoom:video_software_development_kit

Activity : Overall

Related : CVE

  Date Alert Description
7.8 2024-01-12 CVE-2023-49647

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

6.5 2023-12-13 CVE-2023-49646

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

8.8 2023-12-13 CVE-2023-43586

Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.

6.5 2023-12-13 CVE-2023-43585

Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.

4.9 2023-12-13 CVE-2023-43583

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.

7.5 2023-11-14 CVE-2023-39206

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

6.5 2023-11-14 CVE-2023-39205

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

7.5 2023-11-14 CVE-2023-39204

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

7.5 2023-08-08 CVE-2023-39217

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.

7.5 2023-08-08 CVE-2023-36533

Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.

CWE : Common Weakness Enumeration

%idName
40% (2) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...
20% (1) CWE-754 Improper Check for Unusual or Exceptional Conditions
20% (1) CWE-287 Improper Authentication
20% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...