Search CVE reports


Toggle filters

1 – 10 of 38 results


CVE-2026-29068

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than...

1 affected package

pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Vulnerable
Show less packages

CVE-2026-28799

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence...

1 affected package

pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Vulnerable
Show less packages

CVE-2026-26967

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing...

1 affected package

pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Vulnerable
Show less packages

CVE-2026-26203

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams...

1 affected package

pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Vulnerable
Show less packages

CVE-2026-25994

High priority
Fixed

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

1 affected package

pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Fixed
Show less packages

CVE-2025-65102

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may...

1 affected package

pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Vulnerable
Show less packages

CVE-2023-27585

Medium priority

Some fixes available 4 of 7

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not...

2 affected packages

pjproject, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Vulnerable
ring Not in release Fixed Fixed
Show less packages

CVE-2022-23547

Medium priority

Some fixes available 2 of 5

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. This issue is similar to GHSA-9pfh-r8x4-w26w. Possible buffer...

2 affected packages

pjproject, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Vulnerable
ring Not in release Fixed Fixed
Show less packages

CVE-2022-23537

Medium priority

Some fixes available 2 of 11

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted...

4 affected packages

asterisk, pjproject, ring, sip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Vulnerable Not affected Not affected
pjproject Not in release Not in release Vulnerable
ring Not in release Not in release Fixed Fixed
sip Not in release Not in release Not in release
Show less packages

CVE-2022-39269

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media...

3 affected packages

asterisk, pjproject, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Ignored Ignored
pjproject Not in release Not in release Vulnerable
ring Not in release Not in release Ignored Ignored
Show less packages