Zoom 3.5.19689.0629 for Mac OS X

CPE Details

Zoom 3.5.19689.0629 for Mac OS X
3.5.19689.0629
2019-10-31
12h32 +00:00
2020-05-11
17h23 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:zoom:zoom:3.5.19689.0629:*:*:*:*:mac_os_x:*:*

Informations

Vendor

zoom

Product

zoom

Version

3.5.19689.0629

Target Software

mac_os_x

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-22881 2023-03-16 00h00 +00:00 Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
7.5
Haute
CVE-2023-22882 2023-03-16 00h00 +00:00 Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
7.5
Haute
CVE-2021-28133 2021-03-18 12h59 +00:00 Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other meeting participants can briefly see contents of other application windows that were explicitly not shared. The contents of these other windows can (for instance) be seen for a short period of time when they overlay the shared window and get into focus. (An attacker can, of course, use a separate screen-recorder application, unsupported by Zoom, to save all such contents for later replays and analysis.) Depending on the unintentionally shared data, this short exposure of screen contents may be a more or less severe security issue.
4.3
Moyen
CVE-2019-13450 2019-07-09 03h49 +00:00 In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.
6.5
Moyen
CVE-2019-13449 2019-07-09 03h48 +00:00 In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
6.5
Moyen
CVE-2018-15715 2018-11-30 20h00 +00:00 Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
9.8
Critique