CVE-2020-26262
- EPSS 0.34%
- Veröffentlicht 13.01.2021 19:15:16
- Zuletzt bearbeitet 21.11.2024 05:19:41
Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it was observed that when sending ...
CVE-2020-4067
- EPSS 1.1%
- Veröffentlicht 29.06.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:14
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligent...
CVE-2020-6061
- EPSS 1.77%
- Veröffentlicht 19.02.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:00
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS reque...
CVE-2020-6062
- EPSS 8.33%
- Veröffentlicht 19.02.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:00
An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigge...
CVE-2018-4058
- EPSS 0.18%
- Veröffentlicht 21.03.2019 16:00:54
- Zuletzt bearbeitet 21.11.2024 04:06:39
An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loopback interface of its own host. This can provide acc...
- EPSS 0.8%
- Veröffentlicht 21.03.2019 16:00:54
- Zuletzt bearbeitet 21.11.2024 04:06:39
An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide admin...
CVE-2018-4056
- EPSS 0.52%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:39
An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which cou...