Cisco Meeting Server vulnerabilities
27 known vulnerabilities affecting cisco/meeting_server.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH11MEDIUM12
Vulnerabilities
Page 2 of 2
CVE-2017-12311P4MEDIUMCVSS 5.8v2.0v2.1.0+2 more2017-11-16
CVE-2017-12311 [MEDIUM] CWE-399 CVE-2017-12311: A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated
A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server media process to restart unexpectedly when it receives an illegal H.264 frame. The vulnerability is triggered by an H.264 frame that has an invalid picture parameter set (PPS) value. An attacker could
nvd
CVE-2023-20255P4MEDIUMCVSS 5.3fixed in 3.6.12023-11-01
CVE-2023-20255 [MEDIUM] CWE-20 CVE-2023-20255: A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthent
A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP packets to an affected device. A successfu
nvd
CVE-2020-3160P4MEDIUMCVSS 5.3fixed in 2.8.02020-02-19
CVE-2020-3160 [MEDIUM] CWE-20 CVE-2020-3160: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Se
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other applications and processes are unaffected. The vulnerability is due to improper input validation
nvd
CVE-2016-1451P4MEDIUMCVSS 6.1v1.7_basev1.8_base+1 more2016-07-15
CVE-2016-1451 [MEDIUM] CWE-79 CVE-2016-1451: Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Serv
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva19922.
nvd
CVE-2018-0359P4MEDIUMCVSS 5.5v2.3.02018-06-21
CVE-2018-0359 [MEDIUM] CWE-384 CVE-2018-0359: A vulnerability in the session identification management functionality of the web-based management i
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier, aka Session Fixation. The vulnerability exists because the affected application does not assign a new session identifier to a use
nvd
CVE-2019-1794P4MEDIUMCVSS 5.1v2.22019-04-18
CVE-2019-1794 [MEDIUM] CWE-427 CVE-2019-1794: A vulnerability in the search path processing of Cisco Directory Connector could allow an authentica
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Direct
nvd
CVE-2019-1678P4MEDIUMCVSS 4.3v2.3.62019-02-07
CVE-2019-1678 [MEDIUM] CWE-20 CVE-2019-1678: A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a par
A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol (SIP) endpoint. The vulnerability is due to improper validation of coSpaces configuration parameters. An attacker could exploit this vulner
nvd
← Previous2 / 2