VendorsCiscowebex_meetings_serverall versions
Vulnerabilities

Cisco Webex Meetings Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

136CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2020-3361
Cisco Webex Meetings and Cisco Webex Meetings Server Token Handling Unauthorized Access Vulnerability
Published 2020-06-18 · Modified
9.8EPSS 0.024
CVE-2018-0104
A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and persuading the user to follow the link or launch the file. Successful exploitation could allow the attacker to execute arbitrary code on the user's system. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, Cisco WebEx Meetings Server, and Cisco WebEx ARF players. Cisco Bug IDs: CSCvg78853, CSCvg78856, CSCvg78857.
Published 2018-01-04 · Modified
9.6EPSS 0.038
CVE-2017-12368
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploitation of this could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. Cisco Bug IDs: CSCve10584, CSCve10591, CSCve11503, CSCve10658, CSCve11507, CSCve10749, CSCve10744, CSCve11532, CSCve10762, CSCve10764, CSCve11538.
Published 2017-11-30 · Modified
9.6EPSS 0.030
CVE-2017-12372
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploitation of this could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. Cisco Bug IDs: CSCvf57234, CSCvg54868, CSCvg54870.
Published 2017-11-30 · Modified
9.6EPSS 0.030
CVE-2017-12367
A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Exploitation of this could cause an affected player to crash and, in some cases, could allow arbitrary code execution on the system of a targeted user. Cisco Bug IDs: CSCve11545, CSCve02843, CSCve11548.
Published 2017-11-30 · Modified
9.6EPSS 0.028
CVE-2017-3823
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server and Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center) when they are running on Microsoft Windows. The vulnerability is a design defect in an application programing interface (API) response parser within the extension. An attacker that can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser.
Published 2017-02-01 · Modified
9.3EPSS 0.272
CVE-2017-6753
A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037.
Published 2017-07-25 · Modified
9.3EPSS 0.060
CVE-2016-1482
Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130.
Published 2016-09-17 · Modified
9.3EPSS 0.040
CVE-2020-3573
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2020-11-06 · Modified
9.3EPSS 0.028
CVE-2020-3603
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2020-11-06 · Modified
9.3EPSS 0.026
CVE-2020-3127
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2020-03-04 · Modified
9.3EPSS 0.024
CVE-2018-15417
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15414
Cisco Webex Network Recording Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15416
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15415
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15413
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15408
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15412
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15420
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.021
CVE-2018-15422
Cisco Webex Network Recording Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.020
CVE-2018-15418
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.020
CVE-2018-15419
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.020
CVE-2018-15421
Cisco Webex Network Recording Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.020
CVE-2018-15410
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.020
CVE-2018-15411
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
9.3EPSS 0.020
CVE-2020-3194
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerability
Published 2020-04-15 · Modified
9.3EPSS 0.020
CVE-2020-3128
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2020-03-04 · Modified
9.3EPSS 0.019
CVE-2019-15283
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2020-09-23 · Modified
9.3EPSS 0.018
CVE-2019-15285
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2020-09-23 · Modified
9.3EPSS 0.018
CVE-2019-15287
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2020-09-23 · Modified
9.3EPSS 0.018
CVE-2018-0103
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and persuading the user to follow the link or launch the file. Successful exploitation could allow the attacker to execute arbitrary code on the user's system. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, Cisco WebEx Meetings Server, and Cisco WebEx ARF players. Cisco Bug IDs: CSCvg78835, CSCvg78837, CSCvg78839.
Published 2018-01-04 · Modified
9.3EPSS 0.017
CVE-2019-1772
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerability
Published 2019-05-15 · Modified
9.3EPSS 0.017
CVE-2019-1773
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerabilities
Published 2019-05-15 · Modified
9.3EPSS 0.017
CVE-2019-1926
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-08-07 · Modified
9.3EPSS 0.015
CVE-2019-1640
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerabilities
Published 2019-01-23 · Modified
9.3EPSS 0.015
CVE-2019-1639
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerabilities
Published 2019-01-23 · Modified
9.3EPSS 0.015
CVE-2019-1638
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerabilities
Published 2019-01-23 · Modified
9.3EPSS 0.015
CVE-2019-1637
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerabilities
Published 2019-01-23 · Modified
9.3EPSS 0.015
CVE-2019-1924
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-08-07 · Modified
9.3EPSS 0.015
1 / 4Next →