Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.79% | — | Ekiga | 22/4/2019 | 16/6/2026 | Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so. | |
| Modificada | Media (5) | 2.8% | — | Ekiga | 29/9/2014 | 16/6/2026 | lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings. | |
| Modificada | Media (4.3) | 2.9% | — | Opalvoip Portable Tool LibraryEkigaSuse Linux Enterprise Software Development KITSuse Linux Enterprise Desktop | 23/5/2014 | 16/6/2026 | The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka… | |
| Modificada | Media (5) | 11% | 💥 Exploit | EkigaOpenh323 Project Openh323 | 8/10/2007 | 16/6/2026 | The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an… | |
| Modificada | Media (5) | 11% | 💥 Exploit | Ekiga | 14/9/2007 | 16/6/2026 | pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in… | |
| Modificada | Alta (9.3) | 3.5% | — | Gnome Ekiga | 10/3/2007 | 16/6/2026 | Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006. | |
| Modificada | Alta (10) | 7.1% | — | EkigaRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 20/2/2007 | 16/6/2026 | Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function. | |
| Modificada | Alta (10) | 3.7% | — | Ekiga | 20/2/2007 | 16/6/2026 | Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet. |