Opensips

Opensips

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 05.08.2026 00:17:00
  • Zuletzt bearbeitet 05.08.2026 15:16:49

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a mal...

  • EPSS 0.39%
  • Veröffentlicht 04.08.2026 23:30:03
  • Zuletzt bearbeitet 05.08.2026 15:16:48

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by s...

  • EPSS 0.29%
  • Veröffentlicht 04.08.2026 23:16:31
  • Zuletzt bearbeitet 05.08.2026 14:17:06

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boun...

  • EPSS 0.36%
  • Veröffentlicht 04.08.2026 22:48:43
  • Zuletzt bearbeitet 05.08.2026 18:17:11

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte globa...

  • EPSS 0.33%
  • Veröffentlicht 04.08.2026 21:56:57
  • Zuletzt bearbeitet 05.08.2026 19:17:30

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an attacker sen...

  • EPSS 0.59%
  • Veröffentlicht 04.08.2026 21:41:54
  • Zuletzt bearbeitet 05.08.2026 15:16:47

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The size check for {s.b64encode} only verifies that the inpu...

  • EPSS 0.46%
  • Veröffentlicht 04.08.2026 21:23:21
  • Zuletzt bearbeitet 05.08.2026 15:16:47

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the presence module's handle_publish() function processes a SIP PUBLISH request...

  • EPSS 0.48%
  • Veröffentlicht 04.08.2026 20:47:10
  • Zuletzt bearbeitet 05.08.2026 15:16:48

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routing script. F...

  • EPSS 0.32%
  • Veröffentlicht 25.02.2026 16:54:11
  • Zuletzt bearbeitet 14.07.2026 16:16:53

OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwt_db_authorize() function in modules/auth_jwt/authorize.c when db_mode is enabled and a SQL database backend is...

  • EPSS 0.91%
  • Veröffentlicht 15.03.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 07:54:23

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, a specially crafted Authorization header causes OpenSIPS to crash or behave in an unexpected way due to a bug in the function `parse_param_name(...