cbcvebase.

Cisco Webex Meetings Server vulnerabilities

106 known vulnerabilities affecting cisco/webex_meetings_server.

Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH59MEDIUM38LOW1

Vulnerabilities

Page 6 of 6
CVE-2020-3116P4MEDIUMCVSS 5.5v4.02020-09-23
CVE-2020-3116 [MEDIUM] CWE-20 CVE-2020-3116: A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) fi A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email
nvd
CVE-2015-0668P4MEDIUMCVSS 4.3v2.5v2.5.99.22015-03-20
CVE-2015-0668 [MEDIUM] CWE-79 CVE-2015-0668: Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq66737.
nvd
CVE-2014-3296P4MEDIUMCVSS 4.0≤ 1.5\(.1.131\)v1.5\(.1.6\)2014-06-21
CVE-2014-3296 [MEDIUM] CWE-200 CVE-2014-3296: The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
nvd
CVE-2020-3502P4MEDIUMCVSS 4.1v3.0v4.02020-08-17
CVE-2020-3502 [MEDIUM] CWE-20 CVE-2020-3502: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an au Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could explo
nvd
CVE-2020-3501P4MEDIUMCVSS 4.1v3.0v4.02020-08-17
CVE-2020-3501 [MEDIUM] CWE-20 CVE-2020-3501: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an au Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could explo
nvd
CVE-2020-3126P4LOWCVSS 3.5vt39.32020-04-13
CVE-2020-3126 [LOW] CWE-284 CVE-2020-3126: vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authentica vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this vulnerability by using the host role
nvd
Cisco Webex Meetings Server vulnerabilities | cvebase