CVE-2026-90780
- EPSS 0.63%
- Veröffentlicht 13.09.2026 11:42:29
- Zuletzt bearbeitet 23.09.2026 17:17:44
SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages wit...
CVE-2026-90779
- EPSS 0.57%
- Veröffentlicht 13.09.2026 11:42:28
- Zuletzt bearbeitet 23.09.2026 17:17:44
SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the s...
CVE-2026-90778
- EPSS 0.63%
- Veröffentlicht 13.09.2026 11:42:27
- Zuletzt bearbeitet 23.09.2026 17:17:47
SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag paramet...
CVE-2018-25356
- EPSS 0.16%
- Veröffentlicht 23.05.2026 18:30:55
- Zuletzt bearbeitet 06.10.2026 22:10:00
SIPp 3.6 and earlier contains a local buffer overflow vulnerability in command-line argument handling that allows local attackers to crash the application or execute arbitrary code. Attackers can trigger the vulnerability by supplying oversized input...
CVE-2018-25225
- EPSS 0.19%
- Veröffentlicht 28.03.2026 11:58:17
- Zuletzt bearbeitet 07.10.2026 08:10:00
SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values...
CVE-2026-0710
- EPSS 0.22%
- Veröffentlicht 23.01.2026 03:47:44
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol (SIP) messages during an active call. This vulnerability, a NULL pointer dereference, can cause the application to crash, leading ...
CVE-2008-1959
- EPSS 3.49%
- Veröffentlicht 25.04.2008 19:05:00
- Zuletzt bearbeitet 16.06.2026 22:52:50
Stack-based buffer overflow in the get_remote_video_port_media function in call.cpp in SIPp 3.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted SIP message. NOTE: some of these details are obtai...