Pjproject
Pjsip · 47 CVEs
PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and G…
Sep 18, 2026
PJSIP: Heap buffer overflow in the AVI parser
Sep 18, 2026
PJSIP: Pre-authentication overflow in the telnet CLI error
Sep 4, 2026
PJSIP: Pre-authentication overflow in the telnet CLI history
Sep 4, 2026
PJSIP: Heap overflow in the HTTP client
Sep 4, 2026
PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend
Sep 4, 2026
PJSIP: Stack overflow parsing SDP a=crypto attributes
Sep 4, 2026
PJSIP: Stack overflow handling Service-Route headers in a registration response
Sep 4, 2026
PJSIP: SIP message header buffer overflow
Sep 4, 2026
PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance
Sep 4, 2026
GnuTLS backend silently skips certificate chain verification when verify_peer is false
May 7, 2026
PJSIP: Asymmetric ptime integer overflow in Media Stream
Apr 24, 2026
PJSIP: SIP Multipart CID URI Length Underflow
Apr 24, 2026
PJSIP: Stack buffer overflow in pjsip_auth_create_digest2()
Apr 21, 2026
PJSIP: Heap buffer overflow in Opus codec decoding
Apr 21, 2026
PJSIP: Heap OOB read in VPX unpacketizer
Mar 31, 2026
PJSIP has an Out-of-bounds Read in SIP multipart parsing
Mar 20, 2026
PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser
Mar 20, 2026
PJSIP has ICE session use-after-free race conditions
Mar 20, 2026
PJSIP: Heap use-after-free in PJSIP presence subscription termination handler
Mar 6, 2026
PJSIP: Stack buffer overflow in Opus codec parser
Mar 6, 2026
PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer
Feb 20, 2026
PJSIP has a heap buffer overflow in ICE with long username
Feb 11, 2026
PJSIP is vulnerable to buffer overflow in Opus PLC
Nov 21, 2025
PJSIP has use-after-free vulnerability in SRTP media transport
Oct 6, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-84975 | PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends) | HIGH | 0.23% | Sep 18, 2026 |
| CVE-2026-77396 | PJSIP: Heap buffer overflow in the AVI parser | MEDIUM | 0.17% | Sep 18, 2026 |
| CVE-2026-57166 | PJSIP: Pre-authentication overflow in the telnet CLI error | MEDIUM | 0.53% | Sep 4, 2026 |
| CVE-2026-57165 | PJSIP: Pre-authentication overflow in the telnet CLI history | MEDIUM | 0.45% | Sep 4, 2026 |
| CVE-2026-57164 | PJSIP: Heap overflow in the HTTP client | HIGH | 0.45% | Sep 4, 2026 |
| CVE-2026-57163 | PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend | HIGH | 0.40% | Sep 4, 2026 |
| CVE-2026-57162 | PJSIP: Stack overflow parsing SDP a=crypto attributes | HIGH | 0.64% | Sep 4, 2026 |
| CVE-2026-57161 | PJSIP: Stack overflow handling Service-Route headers in a registration response | HIGH | 0.46% | Sep 4, 2026 |
| CVE-2026-57160 | PJSIP: SIP message header buffer overflow | MEDIUM | 0.41% | Sep 4, 2026 |
| CVE-2026-57159 | PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance | HIGH | 0.60% | Sep 4, 2026 |
| CVE-2026-42225 | GnuTLS backend silently skips certificate chain verification when verify_peer is false | HIGH | 0.27% | May 7, 2026 |
| CVE-2026-41416 | PJSIP: Asymmetric ptime integer overflow in Media Stream | HIGH | 0.49% | Apr 24, 2026 |
| CVE-2026-41415 | PJSIP: SIP Multipart CID URI Length Underflow | MEDIUM | 0.54% | Apr 24, 2026 |
| CVE-2026-40892 | PJSIP: Stack buffer overflow in pjsip_auth_create_digest2() | HIGH | 0.60% | Apr 21, 2026 |
| CVE-2026-40614 | PJSIP: Heap buffer overflow in Opus codec decoding | HIGH | 0.37% | Apr 21, 2026 |
| CVE-2026-34235 | PJSIP: Heap OOB read in VPX unpacketizer | MEDIUM | 0.54% | Mar 31, 2026 |
| CVE-2026-33069 | PJSIP has an Out-of-bounds Read in SIP multipart parsing | MEDIUM | 0.43% | Mar 20, 2026 |
| CVE-2026-32945 | PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser | HIGH | 0.54% | Mar 20, 2026 |
| CVE-2026-32942 | PJSIP has ICE session use-after-free race conditions | HIGH | 0.60% | Mar 20, 2026 |
| CVE-2026-28799 | PJSIP: Heap use-after-free in PJSIP presence subscription termination handler | HIGH | 0.51% | Mar 6, 2026 |
| CVE-2026-29068 | PJSIP: Stack buffer overflow in Opus codec parser | HIGH | 0.55% | Mar 6, 2026 |
| CVE-2026-26967 | PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer | HIGH | 0.39% | Feb 20, 2026 |
| CVE-2026-25994 | PJSIP has a heap buffer overflow in ICE with long username | HIGH | 2.06% | Feb 11, 2026 |
| CVE-2025-65102 | PJSIP is vulnerable to buffer overflow in Opus PLC | HIGH | 0.32% | Nov 21, 2025 |
| CVE-2023-38703 | PJSIP has use-after-free vulnerability in SRTP media transport | CRITICAL | 1.59% | Oct 6, 2023 |
Showing 1 to 25 of 47 CVEs