CVE-2023-39201
https://notcve.org/view.php?id=CVE-2023-39201
Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access. La ruta de búsqueda no confiable en CleanZoom antes de la fecha del archivo 24/07/2023 puede permitir a un usuario privilegiado realizar una escalada de privilegios a través del acceso local. • https://explore.zoom.us/en/trust/security/security-bulletin • CWE-426: Untrusted Search Path •
CVE-2023-39208
https://notcve.org/view.php?id=CVE-2023-39208
Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access. Una validación de entrada incorrecta en Zoom Desktop Client para Linux anterior a la versión 5.15.10 puede permitir que un usuario no autenticado realice una denegación de servicio a través del acceso a la red. • https://explore.zoom.us/en/trust/security/security-bulletin • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-39215
https://notcve.org/view.php?id=CVE-2023-39215
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access. Una autenticación inadecuada en los clientes de Zoom puede permitir que un usuario autenticado realice una denegación de servicio a través del acceso a la red. • https://explore.zoom.us/en/trust/security/security-bulletin • CWE-287: Improper Authentication CWE-449: The UI Performs the Wrong Action •
CVE-2023-39209
https://notcve.org/view.php?id=CVE-2023-39209
Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access. • https://explore.zoom.us/en/trust/security/security-bulletin • CWE-20: Improper Input Validation CWE-449: The UI Performs the Wrong Action •
CVE-2023-39214
https://notcve.org/view.php?id=CVE-2023-39214
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access. • https://explore.zoom.us/en/trust/security/security-bulletin • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-668: Exposure of Resource to Wrong Sphere CWE-749: Exposed Dangerous Method or Function •