Search CVE reports


Toggle filters

61 – 70 of 1357 results


CVE-2021-43301

Medium priority

Some fixes available 4 of 15

Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

3 affected packages

asterisk, pjproject, ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
pjproject Fixed
ring Not in release Not in release Fixed Fixed
Show less packages

CVE-2021-43300

Medium priority

Some fixes available 4 of 15

Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

3 affected packages

asterisk, pjproject, ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
pjproject Fixed
ring Not in release Not in release Fixed Fixed
Show less packages

CVE-2021-43299

Medium priority

Some fixes available 4 of 15

Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

3 affected packages

asterisk, pjproject, ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
pjproject Fixed
ring Not in release Not in release Fixed Fixed
Show less packages

CVE-2022-21723

Medium priority

Some fixes available 2 of 5

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message...

2 affected packages

pjproject, ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Vulnerable
ring Not in release Not in release Fixed Fixed
Show less packages

CVE-2022-21722

Medium priority

Some fixes available 1 of 4

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it...

2 affected packages

pjproject, ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Vulnerable
ring Not in release Not in release Fixed Not affected
Show less packages

CVE-2021-22060

Low priority
Needs evaluation

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up...

1 affected package

libspring-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show less packages

CVE-2021-41141

Low priority
Ignored

PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In various parts of PJSIP, when error/failure occurs, it...

1 affected package

ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ring Not in release Not in release Not in release Ignored Ignored
Show less packages

CVE-2021-43845

Medium priority

Some fixes available 2 of 15

PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an...

3 affected packages

pjproject, ring, asterisk

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Vulnerable
ring Not in release Not in release Fixed Fixed
asterisk Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show less packages

CVE-2021-43804

Medium priority

Some fixes available 2 of 5

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE...

2 affected packages

pjproject, ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Vulnerable
ring Not in release Not in release Fixed Fixed
Show less packages

CVE-2021-37706

Medium priority

Some fixes available 6 of 7

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an...

2 affected packages

pjproject, ring

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Fixed
ring Not in release Fixed Fixed
Show less packages