VYPR

Pjsip

by Pjsip

Source repositories

CVEs (53)

  • CVE-2021-43804HigDec 22, 2021
    risk 0.48cvss 7.3epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE message contains a reason's length, this declared length is not…

  • CVE-2021-37706HigDec 22, 2021
    risk 0.48cvss 7.3epss 0.05

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not…

  • CVE-2026-32942HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.01

    PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between session destruction and the callbacks. This issue has been…

  • CVE-2020-15260MedMar 10, 2021
    risk 0.44cvss 6.8epss 0.01

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.10 and earlier, PJSIP transport can be reused if they have the same IP address + port + protocol.…

  • CVE-2026-57159HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.01

    PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in…

  • CVE-2026-41416HigApr 24, 2026
    risk 0.42cvss 7.5epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer…

  • CVE-2026-33069HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past the delimiter without verifying it has not reached…

  • CVE-2021-21375MedMar 10, 2021
    risk 0.42cvss 6.5epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial INVITE has been sent, when two 183 responses are received,…

  • CVE-2026-84975HigSep 18, 2026
    risk 0.41cvss 7.4epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with string functions that recalculate their length…

  • CVE-2021-32686MedJul 23, 2021
    risk 0.39cvss 5.9epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. First, a race condition…

  • CVE-2026-77396MedSep 18, 2026
    risk 0.38cvss —epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame buffer whose capacity is derived from the…

  • CVE-2021-41141MedJan 4, 2022
    risk 0.38cvss 5.9epss 0.01

    PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In various parts of PJSIP, when error/failure occurs, it is found that the function returns without…

  • CVE-2026-42225MedMay 7, 2026
    risk 0.31cvss 5.9epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_transport_tls) can accept connections with invalid or untrusted certificates even when the application explicitly enables…

  • CVE-2026-57160MedSep 4, 2026
    risk 0.27cvss 5.3epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require,…

  • CVE-2026-25994CriFeb 11, 2026
    risk 0.03cvss 9.8epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

  • CVE-2026-29068HigMar 6, 2026
    risk 0.00cvss 7.5epss 0.01

    PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold. This issue has been patched…

  • CVE-2026-28799HigMar 6, 2026
    risk 0.00cvss 7.5epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This…

  • CVE-2026-26967MedFeb 20, 2026
    risk 0.00cvss 5.3epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing malformed SRTP packets, where the unpacketizer…

  • CVE-2026-26203MedFeb 19, 2026
    risk 0.00cvss 6.5epss 0.00

    PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer…

  • CVE-2023-38703CriOct 6, 2023
    risk 0.00cvss 9.8epss 0.01

    PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level media transport such as UDP and ICE. Currently a higher level…