Vulnerabilidades em pjsip
48 resultadosAnálise Vexday
PJSIP acumula 38 vulnerabilidades na base, com 6 críticas (CVSS elevado), sendo a escrita de buffer (CWE-120) a fraqueza predominante; apesar de nenhuma sob ataque ativo registrado no KEV, as 3 publicações nos últimos 90 dias indicam que o componente continua sendo alvo de descobertas recentes. O risco está contido no presente, mas requer monitoramento ativo dado o padrão histórico de vulnerabilidades de memória.
CVE-2022-23537MEDIUMPJSIP vulnerable to heap buffer overflow when decoding STUN messageEPSS 1.0%CVE-2020-15260MEDIUMExisting TLS connections can be reused without checking remote hostnameEPSS 1.0%CVE-2022-23547MEDIUMHeap buffer overflow in pjproject when decoding STUN messageEPSS 0.9%CVE-2026-57162HIGHPJSIP: Stack overflow parsing SDP a=crypto attributesEPSS 0.6%CVE-2022-39269CRITICALMedia transport downgrade from the secure version (SRTP) to non-secure (RTP) in pjsipEPSS 0.6%CVE-2026-40892HIGHPJSIP: Stack buffer overflow in pjsip_auth_create_digest2()EPSS 0.6%CVE-2026-32942HIGHPJSIP has ICE session use-after-free race conditionsEPSS 0.6%CVE-2026-57159HIGHPJSIP: SDP parser out-of-bounds write in remote payload-type map maintenanceEPSS 0.6%CVE-2026-32945HIGHPJSIP is vulnerable to Heap-based Buffer Overflow through DNS parserEPSS 0.5%CVE-2026-41415MEDIUMPJSIP: SIP Multipart CID URI Length UnderflowEPSS 0.5%CVE-2026-34235MEDIUMPJSIP: Heap OOB read in VPX unpacketizerEPSS 0.5%CVE-2026-57166MEDIUMPJSIP: Pre-authentication overflow in the telnet CLI errorEPSS 0.5%CVE-2026-29068HIGHPJSIP: Stack buffer overflow in Opus codec parserEPSS 0.5%CVE-2026-28799HIGHPJSIP: Heap use-after-free in PJSIP presence subscription termination handlerEPSS 0.5%CVE-2026-41416HIGHPJSIP: Asymmetric ptime integer overflow in Media StreamEPSS 0.5%CVE-2026-57161HIGHPJSIP: Stack overflow handling Service-Route headers in a registration responseEPSS 0.5%CVE-2026-57165MEDIUMPJSIP: Pre-authentication overflow in the telnet CLI historyEPSS 0.5%CVE-2026-57164HIGHPJSIP: Heap overflow in the HTTP clientEPSS 0.5%CVE-2026-33069MEDIUMPJSIP has an Out-of-bounds Read in SIP multipart parsingEPSS 0.4%CVE-2026-57160MEDIUMPJSIP: SIP message header buffer overflowEPSS 0.4%