Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2020-27611 BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint. Bigbluebutton after 2.2.28 Fix from $1,9502020-10-21 MEDIUM 6.5 CVE-2020-27607 In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data from the cli… Bigbluebutton 2.2.28+ Fix from $1,6002020-10-21 MEDIUM 6.1 CVE-2020-27608 In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstra… Bigbluebutton 2.2.28+ Fix from $1,6002020-10-21 MEDIUM 5.3 CVE-2020-27606 BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which makes it easier for remote at… Bigbluebutton 2.2.28+ Fix from $1,6002020-10-21 MEDIUM 5.3 CVE-2020-27609 BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data stora… Bigbluebutton after 2.2.28 Fix from $1,6002020-10-21 HIGH 7.5 CVE-2020-27603 BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files. Bigbluebutton 2.2.27+ Fix from $1,9502020-10-21 MEDIUM 6.5 CVE-2020-27604 BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared s… Bigbluebutton 2.2.8+ Fix from $1,6002020-10-21 MEDIUM 6.5 CVE-2020-25820EPSS 10% BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a … Bigbluebutton 2.2.27+ Fix from $1,6002020-10-21 HIGH 8.8 CVE-2020-26163 BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofe… Greenlight 2.5.6+ Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2020-12443 BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while th… Bigbluebutton 2.2.6+ Fix from $2,3002020-04-29 HIGH 7.5 CVE-2020-12112EPSS 5% BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion. Bigbluebutton 2.2.5+ Fix from $1,9502020-04-23 MEDIUM 6.1 CVE-2020-12113 BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used. Bigbluebutton 2.2.4+ Fix from $1,6002020-04-23