2051
|
7.8 |
HIGH
Local
|
zoom
|
rooms
|
Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2023-34119
|
2024-09-20 05:15 |
2023-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2052
|
7.8 |
HIGH
Local
|
zoom
|
rooms
|
Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
|
NVD-CWE-noinfo
|
CVE-2023-34118
|
2024-09-20 05:15 |
2023-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2053
|
8.8 |
HIGH
Network
|
zoom
|
zoom
|
Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.
|
NVD-CWE-noinfo
|
CVE-2023-34116
|
2024-09-20 05:15 |
2023-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2054
|
8.8 |
HIGH
Network
|
zoom
|
zoom rooms virtual_desktop_infrastructure
|
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via …
|
NVD-CWE-noinfo
|
CVE-2023-34121
|
2024-09-20 05:15 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2055
|
7.8 |
HIGH
Local
|
zoom
|
virtual_desktop_infrastructure
|
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privi…
|
NVD-CWE-noinfo
|
CVE-2023-34120
|
2024-09-20 05:15 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2056
|
7.1 |
HIGH
Local
|
zoom
|
virtual_desktop_infrastructure
|
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
|
NVD-CWE-Other
|
CVE-2023-28603
|
2024-09-20 05:15 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2057
|
6.5 |
MEDIUM
Network
|
zoom
|
zoom
|
Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buf…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2023-28601
|
2024-09-20 05:15 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2058
|
5.4 |
MEDIUM
Network
|
zoom
|
zoom
|
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and …
|
NVD-CWE-Other
|
CVE-2023-28600
|
2024-09-20 05:15 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2059
|
6.1 |
MEDIUM
Network
|
mailcow
|
mailcow\
|
mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API l…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41959
|
2024-09-20 05:14 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2060
|
7.5 |
HIGH
Network
oracle
|
weblogic_server
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2023-21839
|
2024-09-20 05:10 |
2023-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|