CVE-2026-40892
- EPSS 0.06%
- Veröffentlicht 21.04.2026 19:55:26
- Zuletzt bearbeitet 23.04.2026 16:07:18
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in PJSIP when using pre-computed digest credentials (PJSIP_CRED_DATA_DIGEST). The functi...
CVE-2026-40614
- EPSS 0.03%
- Veröffentlicht 21.04.2026 18:04:15
- Zuletzt bearbeitet 23.04.2026 16:09:54
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus audio frames due to insufficient buffer size validation in the Opus codec decode path. The FEC decode bu...
CVE-2026-33069
- EPSS 0.05%
- Veröffentlicht 20.03.2026 08:21:51
- Zuletzt bearbeitet 23.03.2026 15:32:13
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past the delimiter without ...
CVE-2026-32945
- EPSS 0.07%
- Veröffentlicht 20.03.2026 03:54:00
- Zuletzt bearbeitet 23.03.2026 20:54:34
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's built-in DNS resolve...
CVE-2026-32942
- EPSS 0.06%
- Veröffentlicht 20.03.2026 03:43:37
- Zuletzt bearbeitet 23.03.2026 20:51:20
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between session destruction and the call...
CVE-2026-28799
- EPSS 0.06%
- Veröffentlicht 06.03.2026 06:36:55
- Zuletzt bearbeitet 10.03.2026 19:44:11
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSC...
CVE-2026-29068
- EPSS 0.06%
- Veröffentlicht 06.03.2026 06:36:45
- Zuletzt bearbeitet 10.03.2026 19:11:53
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold...
CVE-2026-26967
- EPSS 0.01%
- Veröffentlicht 20.02.2026 00:26:54
- Zuletzt bearbeitet 20.02.2026 19:30:22
PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing malformed SRTP packe...
CVE-2026-26203
- EPSS 0.02%
- Veröffentlicht 19.02.2026 19:28:58
- Zuletzt bearbeitet 20.02.2026 20:12:31
PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start...
CVE-2026-25994
- EPSS 0.61%
- Veröffentlicht 11.02.2026 21:16:20
- Zuletzt bearbeitet 19.02.2026 19:23:29
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.