Vulnerabilities > Kamailio > Kamailio > 5.2.2

DATE CVE VULNERABILITY TITLE RISK
2023-03-15 CVE-2020-27507 Classic Buffer Overflow vulnerability in Kamailio
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
network
low complexity
kamailio CWE-120
critical
9.8
2020-11-18 CVE-2020-28361 HTTP Request Smuggling vulnerability in Kamailio
Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters.
network
low complexity
kamailio CWE-444
5.5