Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pjsip — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting pjsip. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PJSIP is an open-source multimedia communication library primarily utilized for developing Voice over IP (VoIP) applications, including softphones and SIP servers. Its widespread adoption in embedded systems and enterprise telephony solutions has resulted in a significant attack surface, evidenced by thirty-seven recorded Common Vulnerabilities and Exposures. Historically, the codebase has been susceptible to critical flaws such as remote code execution, buffer overflows, and denial-of-service conditions, often stemming from inadequate input validation and memory management errors. While not inherently insecure, its complexity and frequent updates have led to periodic security incidents where attackers exploited parsing vulnerabilities to gain unauthorized access or disrupt services. Developers are advised to prioritize regular patching and rigorous code auditing to mitigate these risks, ensuring the integrity of communication infrastructure that relies on this foundational library for real-time audio and video transmission.

Top products by pjsip: pjproject pjmedia-video
CVE ID Title CVSS Severity Published
CVE-2022-39244 Buffer overflow in pjlib scanner and pjmedia — pjproject CWE-120 7.5 High 2022-10-06
CVE-2022-31031 Potential stack buffer overflow when parsing message as a STUN client — pjproject CWE-120 9.8 Critical 2022-06-07
CVE-2022-24792 Potential infinite loop when parsing WAV format file in PJSIP — pjproject CWE-835 7.5 High 2022-04-25
CVE-2022-24793 Potential heap buffer overflow when parsing DNS packets in PJSIP — pjproject CWE-120 7.5 High 2022-04-06
CVE-2022-24786 Potential out-of-bound read/write in PJSIP — pjproject CWE-125 9.8 Critical 2022-04-06
CVE-2022-24763 Infinite Loop in PJSIP — pjproject CWE-835 7.5 High 2022-03-30
CVE-2022-24764 Stack buffer overflow in pjproject — pjproject CWE-120 7.5 High 2022-03-22
CVE-2022-24754 Buffer overflow in pjsip — pjproject CWE-120 8.5 High 2022-03-11
CVE-2022-23608 Use after free in PJSIP — pjproject CWE-416 8.1 High 2022-02-22
CVE-2022-21723 Out-of-bounds read in multipart parsing in PJSIP — pjproject CWE-125 9.1 Critical 2022-01-27
CVE-2022-21722 Potential out-of-bound read during RTP/RTCP parsing in PJSIP — pjproject CWE-125 9.1 Critical 2022-01-27
CVE-2021-41141 Missing release of locks in PJSIP — pjproject CWE-667 5.9 Medium 2022-01-04
CVE-2021-43845 Prevent out-of-bounds read in PJSIP — pjproject CWE-125 8.2 High 2021-12-27
CVE-2021-43804 Out-of-bounds read when parsing RTCP BYE message in PJSIP — pjproject CWE-125 7.3 High 2021-12-22
CVE-2021-37706 Potential integer underflow upon receiving STUN message in PJSIP — pjproject CWE-191 7.3 High 2021-12-22
CVE-2021-32686 Denial of Service in PJSIP — pjproject CWE-362 5.9 Medium 2021-07-23
CVE-2021-21375 Crash in receiving updated SDP answer after initial SDP negotiation failed — pjproject CWE-400 6.5 Medium 2021-03-10
CVE-2020-15260 Existing TLS connections can be reused without checking remote hostname — pjproject CWE-297 6.8 Medium 2021-03-10

This page lists every published CVE security advisory associated with pjsip. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.