Cisco Webex Meetings Online vulnerabilities
57 known vulnerabilities affecting cisco/webex_meetings_online.
Total CVEs
57
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH44MEDIUM13
Vulnerabilities
Page 3 of 3
CVE-2019-1641P3HIGHCVSS 7.8v1.3.33v1.3.39+3 more2019-01-23
CVE-2019-1641 [HIGH] CWE-119 CVE-2019-1641: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An a
nvd
CVE-2019-1771P3HIGHCVSS 7.8fixed in 1.3.422019-05-15
CVE-2019-1771 [HIGH] CWE-119 CVE-2019-1771: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An a
nvd
CVE-2018-15431P3HIGHCVSS 7.3fixed in 1.3.382018-10-05
CVE-2018-15431 [HIGH] CWE-20 CVE-2018-15431: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An
nvd
CVE-2018-0422P3HIGHCVSS 7.3fixed in 1.3.37vt31.20+1 more2018-10-05
CVE-2018-0422 [HIGH] CWE-732 CVE-2018-0422: A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is due to folder permissions that grant a user the permission to read, write, and execute files in th
nvd
CVE-2019-15987P4MEDIUMCVSS 5.3v11.0.02019-11-26
CVE-2019-15987 [MEDIUM] CWE-287 CVE-2019-15987: A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could exploit this vulnerability by se
nvd
CVE-2018-0288P4MEDIUMCVSS 5.3vt31.20vt31.20.22018-05-02
CVE-2018-0288 [MEDIUM] CWE-200 CVE-2018-0288: A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote
A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to a design flaw in Cisco WRF Player. An attacker could explo
nvd
CVE-2021-1525P4MEDIUMCVSS 6.1v41.3.52021-06-04
CVE-2021-1525 [MEDIUM] CWE-601 CVE-2021-1525: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to follow a specially crafted URL th
nvd
CVE-2018-15436P4MEDIUMCVSS 6.1vt33.4.02018-10-05
CVE-2018-15436 [MEDIUM] CWE-79 CVE-2018-15436: A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meet
A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected service. The vul
nvd
CVE-2020-3472P4MEDIUMCVSS 5.0fixed in 40.7.02020-08-17
CVE-2020-3472 [MEDIUM] CWE-200 CVE-2020-3472: A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote
A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within user contacts. An attacker on one Webex Meetings site could exploit this vulnerability by se
nvd
CVE-2020-3463P4MEDIUMCVSS 6.1fixed in 40.2.182020-08-17
CVE-2020-3463 [MEDIUM] CWE-79 CVE-2020-3463: A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthe
A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd
CVE-2018-0457P4MEDIUMCVSS 5.5vt31vt322018-10-05
CVE-2018-0457 [MEDIUM] CWE-399 CVE-2018-0457: A vulnerability in the Cisco Webex Player for Webex Recording Format (WRF) files could allow an unau
A vulnerability in the Cisco Webex Player for Webex Recording Format (WRF) files could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by sending a user a link or email attachment with a malicious WRF file and persuading the user to open the file in the Cisco Webex Pl
nvd
CVE-2019-1680P4MEDIUMCVSS 4.3fixed in 1.3.422019-02-07
CVE-2019-1680 [MEDIUM] CWE-74 CVE-2019-1680: A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inj
A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could exploit this vulnerability by convincing a targeted user to view a malicious URL. A successful exploit could allow the attacker to injec
nvd
CVE-2020-3412P4MEDIUMCVSS 4.3fixed in 40.7.02020-08-17
CVE-2020-3412 [MEDIUM] CWE-284 CVE-2020-3412: A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an aut
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of scheduled meeting templates. An attacker c
nvd
CVE-2020-3413P4MEDIUMCVSS 4.3fixed in 40.7.02020-08-17
CVE-2020-3413 [MEDIUM] CWE-284 CVE-2020-3413: A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an aut
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient authorization enforcement for requests to delete scheduled meeting templates. An attacker cou
nvd
CVE-2021-1517P4MEDIUMCVSS 4.3v41.3.52021-06-04
CVE-2021-1517 [MEDIUM] CWE-693 CVE-2021-1517: A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Se
A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this vulnerability by sharing a file throug
nvd
CVE-2018-0380P4MEDIUMCVSS 5.5vt30vt31+3 more2018-07-18
CVE-2018-0380 [MEDIUM] CWE-399 CVE-2018-0380: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Fo
Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploit
nvd
CVE-2020-3116P4MEDIUMCVSS 5.5v1.3.432020-09-23
CVE-2020-3116 [MEDIUM] CWE-20 CVE-2020-3116: A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) fi
A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email
nvd
← Previous3 / 3