Zoom 4.1.30445.0820 for iPhone OS

CPE Details

Zoom 4.1.30445.0820 for iPhone OS
4.1.30445.0820
2020-04-07
18h17 +00:00
2020-04-07
18h17 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:zoom:zoom:4.1.30445.0820:*:*:*:*:iphone_os:*:*

Informations

Vendor

zoom

Product

zoom

Version

4.1.30445.0820

Target Software

iphone_os

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-24690 2024-02-14 00h00 +00:00 Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
6.5
Moyen
CVE-2024-24699 2024-02-13 23h58 +00:00 Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
6.5
Moyen
CVE-2024-24698 2024-02-13 23h56 +00:00 Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
4.9
Moyen
CVE-2023-49646 2023-12-13 22h19 +00:00 Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
6.5
Moyen
CVE-2023-43585 2023-12-13 22h15 +00:00 Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
7.1
Haute
CVE-2023-43583 2023-12-13 22h08 +00:00 Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.
4.9
Moyen
CVE-2023-43582 2023-11-14 23h12 +00:00 Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
8.8
Haute
CVE-2023-39199 2023-11-14 23h06 +00:00 Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
6.5
Moyen
CVE-2023-39206 2023-11-14 23h02 +00:00 Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
7.5
Haute
CVE-2023-39205 2023-11-14 22h32 +00:00 Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
6.5
Moyen
CVE-2023-39204 2023-11-14 22h28 +00:00 Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
7.5
Haute
CVE-2023-39215 2023-09-12 19h53 +00:00 Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
7.1
Haute
CVE-2023-39214 2023-08-08 21h38 +00:00 Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
8.1
Haute
CVE-2023-39218 2023-08-08 17h54 +00:00 Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.
6.1
Moyen
CVE-2023-36535 2023-08-08 17h39 +00:00 Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.
7.1
Haute
CVE-2023-36532 2023-08-08 17h30 +00:00 Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.
7.5
Haute
CVE-2023-28599 2023-06-13 16h55 +00:00 Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
4.3
Moyen
CVE-2023-28597 2023-03-27 00h00 +00:00 Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.
8.3
Haute
CVE-2023-22881 2023-03-16 00h00 +00:00 Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
7.5
Haute
CVE-2023-22882 2023-03-16 00h00 +00:00 Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
7.5
Haute
CVE-2022-28755 2022-08-11 14h55 +00:00 The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.
9.6
Critique
CVE-2021-28133 2021-03-18 12h59 +00:00 Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other meeting participants can briefly see contents of other application windows that were explicitly not shared. The contents of these other windows can (for instance) be seen for a short period of time when they overlay the shared window and get into focus. (An attacker can, of course, use a separate screen-recorder application, unsupported by Zoom, to save all such contents for later replays and analysis.) Depending on the unintentionally shared data, this short exposure of screen contents may be a more or less severe security issue.
4.3
Moyen