cbcvebase.

Cisco Jabber vulnerabilities

31 known vulnerabilities affecting cisco/jabber.

Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH5MEDIUM20

Vulnerabilities

Page 2 of 2
CVE-2015-6409P4MEDIUMCVSS 5.9v10.6\(2\)2015-12-26
CVE-2015-6409 [MEDIUM] CWE-200 CVE-2015-6409: Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STA Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.
nvd
CVE-2017-12356P4MEDIUMCVSS 6.1v10.5\(2\)v11.9\(1\)2017-11-30
CVE-2017-12356 [MEDIUM] CWE-79 CVE-2017-12356: A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input b
nvd
CVE-2018-0483P4MEDIUMCVSS 5.4v10.0\(0\)2019-01-10
CVE-2018-0483 [MEDIUM] CWE-79 CVE-2018-0483: A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supplied input of an affected client. An attacker could exploit this vulnerability by executing arbitrary Ja
nvd
CVE-2017-12286P4MEDIUMCVSS 5.5v1.9.302017-10-19
CVE-2017-12286 [MEDIUM] CWE-20 CVE-2017-12286: A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software. An attacker could exploit this vu
nvd
CVE-2015-4218P4MEDIUMCVSS 5.0v9.6\(0\)v9.6\(1\)+8 more2015-06-24
CVE-2015-4218 [MEDIUM] CWE-200 CVE-2015-4218: The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
nvd
CVE-2017-12358P4MEDIUMCVSS 5.4v11.9\(0\)2017-11-30
CVE-2017-12358 [MEDIUM] CWE-79 CVE-2017-12358: A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based manageme
nvd
CVE-2017-12284P4MEDIUMCVSS 5.5v11.8\(.4\)2017-10-19
CVE-2017-12284 [MEDIUM] CWE-200 CVE-2017-12284: A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input- and validation-checking mechanisms in the system. An attacker could exploit this vulner
nvd
CVE-2018-0201P4MEDIUMCVSS 5.4v11.9v11.9\(.0\)2018-02-22
CVE-2018-0201 [MEDIUM] CWE-79 CVE-2018-0201: A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of input during web page generation. An attacker could exploit this vulnerability by embedding media in instant mess
nvd
CVE-2022-20917P4MEDIUMCVSS 4.3fixed in 12.6.6fixed in 12.8.8+7 more2023-09-15
CVE-2022-20917 [MEDIUM] CWE-668 CVE-2022-20917: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP messages within requests that are sent
nvd
CVE-2018-0449P4MEDIUMCVSS 4.2v12.1\(0\)2019-01-10
CVE-2018-0449 [MEDIUM] CWE-275 CVE-2018-0449: A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated privileges. The vulnerability exists due to insecure directory permissions set on a JCF created directory. An authentic
nvd
CVE-2017-12361P4MEDIUMCVSS 4.0v11.8\(0\)v11.8\(1\)+2 more2017-11-30
CVE-2017-12361 [MEDIUM] CWE-200 CVE-2017-12361: A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information to conduct additional attacks. The vulnerability is due to the way Cisco Jabber for Windows handles random number generation for file
nvd
Cisco Jabber vulnerabilities | cvebase