CVE-2011-1830
- EPSS 0.2%
- Published 22.04.2019 16:29:00
- Last modified 21.11.2024 01:27:08
Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.
- EPSS 1.36%
- Published 29.09.2014 22:55:05
- Last modified 12.04.2025 10:46:40
lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.
CVE-2013-1864
- EPSS 2.73%
- Published 23.05.2014 14:55:09
- Last modified 12.04.2025 10:46:40
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXM...
- EPSS 22.67%
- Published 08.10.2007 21:17:00
- Last modified 09.04.2025 00:30:58
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) ...
- EPSS 22.27%
- Published 14.09.2007 18:17:00
- Last modified 09.04.2025 00:30:58
pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was ori...
- EPSS 12.34%
- Published 20.02.2007 17:28:00
- Last modified 09.04.2025 00:30:58
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting...
- EPSS 3.74%
- Published 20.02.2007 01:28:00
- Last modified 09.04.2025 00:30:58
Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.