📦

osip

Vendor: gnu

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 70 Total Indexed
Avg. EPSS 1.60% Exploit Prob.
Latest CVE CVE-2022-41550 Oct 11

Security Vulnerability Index

Page 1 / 7
6.5 CVSS

GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

EPSS: 0.54%
7.5 CVSS

In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS.

EPSS: 2.46%
7.5 CVSS

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

EPSS: 1.50%
7.5 CVSS

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.

EPSS: 1.50%
9.8 CVSS

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.

EPSS: 2.01%