本ページは zoom rooms_controller に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2025-64739 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. | [email protected] | 4.3 | 0.06% | 2025-11-13 | 2026-01-13 |
| CVE-2025-62483 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. | [email protected] | 5.3 | 0.05% | 2025-11-13 | 2026-01-13 |
| CVE-2025-58135 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. | [email protected] | 5.3 | 0.07% | 2025-09-09 | 2025-10-06 |
| CVE-2025-58134 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. | [email protected] | 4.3 | 0.03% | 2025-09-09 | 2025-10-06 |
| CVE-2025-49461 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | [email protected] | 4.3 | 0.05% | 2025-09-09 | 2025-10-06 |
| CVE-2025-49460 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | [email protected] | 4.3 | 0.06% | 2025-09-09 | 2025-10-17 |
| CVE-2025-49458 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.05% | 2025-09-09 | 2025-10-17 |
| CVE-2025-49457 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | [email protected] | 9.6 | 0.16% | 2025-08-12 | 2025-09-08 |
| CVE-2025-49456 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. | [email protected] | 6.2 | 0.02% | 2025-08-12 | 2025-09-08 |
| CVE-2025-46786 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. | [email protected] | 4.3 | 0.18% | 2025-05-14 | 2025-11-06 |
| CVE-2025-46785 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.31% | 2025-05-14 | 2025-08-19 |
| CVE-2025-30668 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.31% | 2025-05-14 | 2025-11-04 |
| CVE-2025-30667 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.31% | 2025-05-14 | 2025-11-04 |
| CVE-2025-30666 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.31% | 2025-05-14 | 2025-08-05 |
| CVE-2025-30665 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.31% | 2025-05-14 | 2025-08-05 |
| CVE-2025-30664 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. | [email protected] | 6.6 | 0.07% | 2025-05-14 | 2025-11-06 |
| CVE-2025-30663 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. | [email protected] | 8.8 | 0.01% | 2025-05-14 | 2025-11-06 |
| CVE-2025-30671 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.31% | 2025-04-08 | 2025-08-01 |
| CVE-2025-30670 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | [email protected] | 6.5 | 0.37% | 2025-04-08 | 2025-08-01 |
| CVE-2025-27443 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. | [email protected] | 2.8 | 0.14% | 2025-04-08 | 2025-08-01 |