Vulnerabilities > Drachtio

DATE CVE VULNERABILITY TITLE RISK
2022-12-18 CVE-2022-47516 Reachable Assertion vulnerability in Drachtio Drachtio-Server
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.20.
network
low complexity
drachtio CWE-617
7.5
2022-12-18 CVE-2022-47517 Off-by-one Error vulnerability in Drachtio Drachtio-Server
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19.
network
low complexity
drachtio CWE-193
7.5
2022-11-26 CVE-2022-45909 Out-of-bounds Read vulnerability in Drachtio Drachtio-Server
drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request.
network
low complexity
drachtio CWE-125
critical
9.1
2022-11-18 CVE-2022-45473 Unspecified vulnerability in Drachtio Drachtio-Server 0.8.18
In drachtio-server 0.8.18, /var/log/drachtio has mode 0777 and drachtio.log has mode 0666.
local
low complexity
drachtio
5.5
2022-11-18 CVE-2022-45474 Use After Free vulnerability in Drachtio Drachtio-Server 0.8.18
drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request.
network
low complexity
drachtio CWE-416
critical
9.8