Filtered by vendor Trueconf Subscriptions
Filtered by product Trueconf Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-72529 1 Trueconf 2 Trueconf, Trueconf Server 2026-08-21 9.8 Critical
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
CVE-2026-3502 1 Trueconf 1 Trueconf 2026-04-03 7.8 High
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
CVE-2025-66835 1 Trueconf 1 Trueconf 2026-01-09 7.1 High
TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context.