cbcvebase.

Cisco Webex Meetings vulnerabilities

51 known vulnerabilities affecting cisco/webex_meetings.

Total CVEs
51
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH14MEDIUM29

Vulnerabilities

Page 1 of 3
CVE-2019-1674P2HIGHCVSS 8.8PoCfixed in 33.6.62019-02-28
CVE-2019-1674 [HIGH] CWE-78 CVE-2019-1674: A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivi A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking
nvd
CVE-2020-3361P2CRITICALCVSS 9.8≤ 39.5.25≥ 40.1.0, ≤ 40.4.10+1 more2020-06-18
CVE-2020-3361 [CRITICAL] CWE-287 CVE-2020-3361: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to
nvd
CVE-2018-0264P3CRITICALCVSS 9.6fixed in t32.122018-05-02
CVE-2018-0264 [CRITICAL] CWE-20 CVE-2018-0264: A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) file A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and persuading the user
nvd
CVE-2020-3342P3HIGHCVSS 8.8fixed in 39.5.112020-06-18
CVE-2020-3342 [HIGH] CWE-295 CVE-2020-3342: A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could all A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to improper validation of cryptographic protections on files that are downloaded by the application as part of a software update. An attacker
nvd
CVE-2017-12368P3CRITICALCVSS 9.6vt29vt30+2 more2017-11-30
CVE-2017-12368 [CRITICAL] CWE-119 CVE-2017-12368: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx N A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file
nvd
CVE-2017-12372P3CRITICALCVSS 9.6vt29vt30+1 more2017-11-30
CVE-2017-12372 [CRITICAL] CWE-119 CVE-2017-12372: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx N A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file
nvd
CVE-2017-12370P3CRITICALCVSS 9.6vt30vt312017-11-30
CVE-2017-12370 [CRITICAL] CWE-119 CVE-2017-12370: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx N A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file
nvd
CVE-2017-12371P3CRITICALCVSS 9.6vt30vt312017-11-30
CVE-2017-12371 [CRITICAL] CWE-119 CVE-2017-12371: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx N A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file
nvd
CVE-2017-6753P3HIGHCVSS 8.8vt30_base2017-07-25
CVE-2017-6753 [HIGH] CWE-119 CVE-2017-6753: A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event C
nvd
CVE-2018-0112P3CRITICALCVSS 9.0vt312018-04-19
CVE-2018-0112 [CRITICAL] CWE-20 CVE-2018-0112: A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meeting A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to insufficient input validation by the Cisco WebEx clients. An attacker could exploit this vulnerability by providing meeti
nvd
CVE-2017-12369P3CRITICALCVSS 9.6vt29vt30+2 more2017-11-30
CVE-2017-12369 [CRITICAL] CWE-119 CVE-2017-12369: A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network R A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploi
nvd
CVE-2020-3263P3HIGHCVSS 7.5fixed in 39.5.122020-06-18
CVE-2020-3263 [HIGH] CWE-20 CVE-2020-3263: A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user system. The vulnerability is due to improper validation of input that is supplied to application URLs. The attacker could exploit this vulnerability by persuading a user to follow a malicious URL. A successful exp
nvd
CVE-2020-3573P3HIGHCVSS 7.8≥ 40.6.0, < 40.6.11≥ 40.7.0, < 40.8.02020-11-06
CVE-2020-3573 [HIGH] CWE-119 CVE-2020-3573: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3603P3HIGHCVSS 7.8fixed in 40.6.11≥ 40.7.0, < 40.8.02020-11-06
CVE-2020-3603 [HIGH] CWE-119 CVE-2020-3603: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3604P3HIGHCVSS 7.8fixed in 40.6.11≥ 40.7.0, < 40.8.02020-11-06
CVE-2020-3604 [HIGH] CWE-119 CVE-2020-3604: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3127P3HIGHCVSS 7.8≥ 39.5, < 39.5.172020-03-04
CVE-2020-3127 [HIGH] CWE-20 CVE-2020-3127: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored in either the Advanced Recording For
nvd
CVE-2020-3128P3HIGHCVSS 7.8≥ 39.5, < 39.5.172020-03-04
CVE-2020-3128 [HIGH] CWE-20 CVE-2020-3128: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored in either the Advanced Recording For
nvd
CVE-2019-15287P3HIGHCVSS 7.8≥ 39.5.0, < 39.5.122020-09-23
CVE-2019-15287 [HIGH] CWE-119 CVE-2019-15287: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
CVE-2019-15283P3HIGHCVSS 7.8≥ 39.5.0, < 39.5.122020-09-23
CVE-2019-15283 [HIGH] CWE-119 CVE-2019-15283: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
CVE-2019-15285P3HIGHCVSS 7.8≥ 39.5.0, < 39.5.122020-09-23
CVE-2019-15285 [HIGH] CWE-119 CVE-2019-15285: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
Cisco Webex Meetings vulnerabilities | cvebase