Cisco Webex Meetings Server vulnerabilities
106 known vulnerabilities affecting cisco/webex_meetings_server.
Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH59MEDIUM38LOW1
Vulnerabilities
Page 6 of 6
CVE-2020-3116P4MEDIUMCVSS 5.5v4.02020-09-23
CVE-2020-3116 [MEDIUM] CWE-20 CVE-2020-3116: A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) fi
A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email
nvd
CVE-2015-0668P4MEDIUMCVSS 4.3v2.5v2.5.99.22015-03-20
CVE-2015-0668 [MEDIUM] CWE-79 CVE-2015-0668: Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server
Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq66737.
nvd
CVE-2014-3296P4MEDIUMCVSS 4.0≤ 1.5\(.1.131\)v1.5\(.1.6\)2014-06-21
CVE-2014-3296 [MEDIUM] CWE-200 CVE-2014-3296: The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
nvd
CVE-2020-3502P4MEDIUMCVSS 4.1v3.0v4.02020-08-17
CVE-2020-3502 [MEDIUM] CWE-20 CVE-2020-3502: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an au
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could explo
nvd
CVE-2020-3501P4MEDIUMCVSS 4.1v3.0v4.02020-08-17
CVE-2020-3501 [MEDIUM] CWE-20 CVE-2020-3501: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an au
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could explo
nvd
CVE-2020-3126P4LOWCVSS 3.5vt39.32020-04-13
CVE-2020-3126 [LOW] CWE-284 CVE-2020-3126: vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authentica
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this vulnerability by using the host role
nvd
← Previous6 / 6