Search CVE reports


Toggle filters

41 – 50 of 1350 results


CVE-2022-23547

Medium priority

Some fixes available 2 of 5

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. This issue is similar to GHSA-9pfh-r8x4-w26w. Possible buffer...

2 affected packages

ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ring Not in release Fixed Fixed
pjproject Not in release Not in release Needs evaluation
Show less packages

CVE-2022-23537

Medium priority

Some fixes available 2 of 11

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted...

4 affected packages

asterisk, ring, pjproject, sip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Vulnerable Not affected Not affected
ring Not in release Not in release Fixed Fixed
pjproject Not in release Not in release Vulnerable
sip Not in release Not in release Not in release
Show less packages

CVE-2022-22978

Medium priority
Needs evaluation

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with...

2 affected packages

libspring-java, libspring-security-2.0-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libspring-security-2.0-java
Show less packages

CVE-2022-22976

Medium priority
Needs evaluation

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not...

2 affected packages

libspring-java, libspring-security-2.0-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libspring-security-2.0-java
Show less packages

CVE-2022-22971

Low priority
Needs evaluation

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-22970

Low priority
Needs evaluation

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-22968

Medium priority
Needs evaluation

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-22965

High priority

Some fixes available 6 of 10

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-22950

Medium priority
Needs evaluation

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-21723

Medium priority

Some fixes available 2 of 5

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message...

2 affected packages

ring, pjproject

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ring Not in release Fixed Fixed
pjproject Needs evaluation
Show less packages