Vulnerabilities in OpenSIPS

20 results
Vexday analysis

OpenSIPS apresenta 12 vulnerabilidades catalogadas, todas de severidade abaixo de crítica, sem registros de exploração ativa ou publicações recentes. A fraqueza dominante é validação inadequada de entrada (CWE-20), indicando risco moderado em cenários de acesso não autenticado, mas sem urgência imediata de remediação.

CVE-2023-27600HIGHOpenSIPS has vulnerability in the codec_delete_XX() functionsEPSS 1.0%CVE-2023-27601HIGHOpenSIPS has vulnerability in the codec_delete_XX() functionsEPSS 1.0%CVE-2023-27598HIGHOpenSIPS has vulnerability in the parse_via() functionEPSS 1.0%CVE-2023-27599HIGHOpenSIPS has vulnerability in the parse_to_param() functionEPSS 1.0%CVE-2023-28095HIGHOpenSIPS has vulnerability in the building the local negative repliesEPSS 1.0%CVE-2023-28097HIGHOpenSIPS has vulnerability in the Content-Length ParserEPSS 1.0%CVE-2023-28099MEDIUMOpenSIPS has vulnerability in the ds_is_in_list() functionEPSS 0.9%CVE-2023-28098MEDIUMOpenSIPS has vulnerability in the Digest Authentication ParserEPSS 0.9%CVE-2023-28096MEDIUMOpenSIPS has memory leak in cJSON libEPSS 0.8%CVE-2023-27596HIGHOpenSIPS has vulnerability in the codec_delete_XX() functionsEPSS 0.7%CVE-2023-27597HIGHOpenSIPS has vulnerability in the parse_uri() functionEPSS 0.7%CVE-2026-45100CRITICALOpenSIPS: Buffer Overflow in Base64 Encode TransformationEPSS 0.7%CVE-2026-45538CRITICALOpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name CopyEPSS 0.6%CVE-2026-46334HIGHOpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloningEPSS 0.5%CVE-2026-45084HIGHOpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type stateEPSS 0.5%CVE-2026-45809HIGHOpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URIEPSS 0.4%CVE-2026-45537CRITICALOpenSIPS: Global Buffer Overflow in construct_uriEPSS 0.4%CVE-2026-45103HIGHOpenSIPS: SIP Message Smuggling via TCP Content-Length Integer OverflowEPSS 0.3%CVE-2026-25554HIGHOpenSIPS 3.1 <= 3.6.4 auth_jwt SQL Injection Enables JWT Authentication BypassEPSS 0.3%CVE-2026-45705MEDIUMOpenSIPS: OOB Read in Multipart Body Boundary ParsingEPSS 0.3%