Cisco
Cisco Jabber: vulnerabilidades y CVE
Cisco Jabber tiene 34 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE34
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-20917 | Media (4.3) | 0.89% | — | 15 sept 2023 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used… |
| CVE-2021-1570 | Media (6.5) | 0.79% | — | 16 jun 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For… |
| CVE-2021-1569 | Media (6.5) | 0.80% | — | 16 jun 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For… |
| CVE-2021-1418 | Media (6.5) | 0.94% | — | 24 mar 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated… |
| CVE-2021-1417 | Media (6.5) | 0.96% | — | 24 mar 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated… |
| CVE-2021-1411 | Crítica (9.9) | 1.4% | — | 24 mar 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated… |
| CVE-2021-1471 | Media (5.6) | 1.3% | — | 24 mar 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated… |
| CVE-2021-1469 | Alta (7.2) | 1.0% | — | 24 mar 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated… |
| CVE-2020-26085 | Crítica (9.9) | 2.2% | — | 7 ene 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated… |
| CVE-2020-27134 | Crítica (9.9) | 1.7% | — | 11 dic 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated… |
| CVE-2020-27133 | Crítica (9.9) | 1.1% | — | 11 dic 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated… |
| CVE-2020-27132 | Crítica (9.9) | 1.4% | — | 11 dic 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated… |
| CVE-2020-27127 | Crítica (9.9) | 1.4% | — | 11 dic 2020 | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated… |
| CVE-2020-3537 | Media (5.7) | 1.3% | — | 4 sept 2020 | A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An… |
| CVE-2020-3498 | Media (6.5) | 1.6% | — | 4 sept 2020 | A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could… |
| CVE-2020-3495 | Alta (8.8) | 60% | — | 4 sept 2020 | A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this… |
| CVE-2020-3430 | Alta (8.8) | 3.9% | — | 4 sept 2020 | A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper handling of… |
| CVE-2020-3155 | Alta (7.4) | 0.90% | — | 4 mar 2020 | A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco… |
| CVE-2019-12645 | Alta (7.8) | 0.31% | — | 5 sept 2019 | A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to execute arbitrary code on an affected device… |
| CVE-2019-1855 | Alta (7.3) | 2.3% | — | 4 jul 2019 | A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading attack. To exploit this vulnerability, the… |
| CVE-2018-0483 | Media (5.4) | 0.88% | — | 10 ene 2019 | A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to… |
| CVE-2018-0449 | Media (4.2) | 0.28% | — | 10 ene 2019 | A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device… |
| CVE-2018-0201 | Media (5.4) | 0.89% | — | 22 feb 2018 | A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to… |
| CVE-2018-0199 | Media (6.1) | 2.0% | — | 22 feb 2018 | A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to… |
| CVE-2017-12361 | Media (4) | 0.39% | — | 30 nov 2017 | A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information… |
| CVE-2017-12358 | Media (5.4) | 0.64% | — | 30 nov 2017 | A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the… |
| CVE-2017-12356 | Media (6.1) | 1.2% | — | 30 nov 2017 | A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of… |
| CVE-2017-12286 | Media (5.5) | 0.36% | — | 19 oct 2017 | A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential… |
| CVE-2017-12284 | Media (5.5) | 0.36% | — | 19 oct 2017 | A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confidential information.… |
| CVE-2015-6409 | Media (5.9) | 1.3% | — | 26 dic 2015 | Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419. |