Janus
Meetecho · 13 CVEs
Cross-site Scripting (XSS) - Stored in meetecho/janus-gateway
Dec 16, 2021
Cross-site Scripting (XSS) - Stored in meetecho/janus-gateway
Nov 27, 2021
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in pl…
Jun 15, 2020
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c h…
Jun 15, 2020
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack…
Jun 10, 2020
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NU…
Jun 10, 2020
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in ja…
Jun 10, 2020
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NUL…
Jun 10, 2020
An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private room…
Mar 14, 2020
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "que…
Mar 14, 2020
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition…
Mar 14, 2020
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property…
Mar 14, 2020
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session ma…
Mar 14, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-4124 | Cross-site Scripting (XSS) - Stored in meetecho/janus-gateway | MEDIUM | 0.94% | Dec 16, 2021 |
| CVE-2021-4020 | Cross-site Scripting (XSS) - Stored in meetecho/janus-gateway | MEDIUM | 0.84% | Nov 27, 2021 |
| CVE-2020-14033 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Ove… | CRITICAL | 1.90% | Jun 15, 2020 |
| CVE-2020-14034 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in a… | CRITICAL | 2.29% | Jun 15, 2020 |
| CVE-2020-13901 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow. | CRITICAL | 2.58% | Jun 10, 2020 |
| CVE-2020-13900 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer dereference. | HIGH | 2.37% | Jun 10, 2020 |
| CVE-2020-13899 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uniniti… | HIGH | 2.14% | Jun 10, 2020 |
| CVE-2020-13898 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference. | HIGH | 2.31% | Jun 10, 2020 |
| CVE-2020-10573 | An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge. | HIGH | 0.97% | Mar 14, 2020 |
| CVE-2020-10574 | An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of… | CRITICAL | 1.42% | Mar 14, 2020 |
| CVE-2020-10576 | An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash. | MEDIUM | 0.65% | Mar 14, 2020 |
| CVE-2020-10577 | An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race conditi… | MEDIUM | 0.47% | Mar 14, 2020 |
| CVE-2020-10575 | An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes… | MEDIUM | 0.47% | Mar 14, 2020 |
Showing 1 to 13 of 13 CVEs