Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigbluebutton HIGH 7.3
CVE-2020-27611

BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.

Fix: after 2.2.28
Fix from $1,950 2020-10-21
Bigbluebutton MEDIUM 6.5
CVE-2020-27607

In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data from the cli…

Fix: 2.2.28+
Fix from $1,600 2020-10-21
Bigbluebutton MEDIUM 6.1
CVE-2020-27608

In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstra…

Fix: 2.2.28+
Fix from $1,600 2020-10-21
Bigbluebutton MEDIUM 5.3
CVE-2020-27606

BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which makes it easier for remote at…

Fix: 2.2.28+
Fix from $1,600 2020-10-21
Bigbluebutton MEDIUM 5.3
CVE-2020-27609

BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data stora…

Fix: after 2.2.28
Fix from $1,600 2020-10-21
Bigbluebutton HIGH 7.5
CVE-2020-27603

BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.

Fix: 2.2.27+
Fix from $1,950 2020-10-21
Bigbluebutton MEDIUM 6.5
CVE-2020-27604

BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared s…

Fix: 2.2.8+
Fix from $1,600 2020-10-21
Bigbluebutton MEDIUM 6.5
CVE-2020-25820EPSS 10%

BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a …

Fix: 2.2.27+
Fix from $1,600 2020-10-21
Greenlight HIGH 8.8
CVE-2020-26163

BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofe…

Fix: 2.5.6+
Fix from $1,950 2020-09-30
Bigbluebutton CRITICAL 9.8
CVE-2020-12443

BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while th…

Fix: 2.2.6+
Fix from $2,300 2020-04-29
Bigbluebutton HIGH 7.5
CVE-2020-12112EPSS 5%

BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.

Fix: 2.2.5+
Fix from $1,950 2020-04-23
Bigbluebutton MEDIUM 6.1
CVE-2020-12113

BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

Fix: 2.2.4+
Fix from $1,600 2020-04-23