Search CVE reports


Toggle filters

51 – 60 of 1351 results


CVE-2022-21723

Medium priority

Some fixes available 2 of 5

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message...

2 affected packages

ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages

CVE-2022-21722

Medium priority

Some fixes available 1 of 4

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it...

2 affected packages

ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ring Not in release Fixed Not affected
pjproject Needs evaluation
Show less packages

CVE-2021-43845

Medium priority

Some fixes available 2 of 16

PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an...

3 affected packages

asterisk, ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages

CVE-2021-43804

Medium priority

Some fixes available 2 of 5

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE...

2 affected packages

ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages

CVE-2021-43519

Low priority
Needs evaluation

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

45 affected packages

lua50, lua5.1, lua5.2, lua5.3, lua5.4...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua50 Not in release Not in release Not affected Not affected
lua5.1 Not affected Not affected Not affected Not affected
lua5.2 Not affected Not affected Not affected Not affected
lua5.3 Not affected Not affected Not affected Not affected
lua5.4 Not affected Not affected Not in release Not in release
syslinux Not affected Not affected Not affected Not affected
syslinux-legacy Not in release Not in release Not affected Not affected
grub2 Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
ceph Not affected Not affected Not affected Not affected
luajit Not affected Not affected Not affected Not affected
redis Not affected Not affected Not affected Not affected
openscenegraph Not affected Not affected Not affected Not affected
freeciv Not affected Not affected Not affected Not affected
ardour Not affected Not affected Not affected Not affected
ufoai Not affected Not affected Not affected Not affected
gtk2-engines Not affected Not affected Not affected Not affected
scummvm Not affected Not affected Not affected Not affected
mame Not affected Not affected Not affected Not affected
tagua Not affected Not affected Not affected Not affected
enigma Not affected Not affected Not affected Not affected
haskell-hslua Not affected Not affected Not affected Not affected
hedgewars Not affected Not affected Not affected Not affected
xmoto Not affected Not affected Not affected Not affected
spring Not affected Not affected Not affected Not affected
fs-uae Needs evaluation Needs evaluation Needs evaluation Needs evaluation
scorched3d Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freedroidrpg Needs evaluation Needs evaluation Needs evaluation Needs evaluation
blobby Needs evaluation Needs evaluation Needs evaluation Needs evaluation
widelands Needs evaluation Needs evaluation Needs evaluation Needs evaluation
naev Needs evaluation Needs evaluation Needs evaluation
tarantool Needs evaluation Needs evaluation Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
scite Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vifm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golly Needs evaluation Needs evaluation Needs evaluation Needs evaluation
goxel Needs evaluation Needs evaluation Needs evaluation Needs evaluation
emscripten Needs evaluation Needs evaluation Needs evaluation
tup Needs evaluation Needs evaluation Needs evaluation
bam Needs evaluation Needs evaluation Needs evaluation Needs evaluation
wcc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rust-lua52-sys Needs evaluation Needs evaluation Needs evaluation
eja Not in release Needs evaluation Needs evaluation Needs evaluation
zfs-linux Not affected Not affected Not affected Not affected
wesnoth
Show all 45 packages Show less packages

CVE-2021-43303

Medium priority

Some fixes available 2 of 16

Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer,...

3 affected packages

asterisk, ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages

CVE-2021-43302

Medium priority

Some fixes available 2 of 16

Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when the filename is shorter than 4 characters.

3 affected packages

asterisk, ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages

CVE-2021-43301

Medium priority

Some fixes available 2 of 16

Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

3 affected packages

asterisk, ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages

CVE-2021-43300

Medium priority

Some fixes available 2 of 16

Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

3 affected packages

asterisk, ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages

CVE-2021-43299

Medium priority

Some fixes available 2 of 16

Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

3 affected packages

asterisk, ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages