Vulnerabilities > Openh323 Project

DATE CVE VULNERABILITY TITLE RISK
2007-10-08 CVE-2007-4924 Improper Input Validation vulnerability in multiple products
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
network
low complexity
ekiga openh323-project CWE-20
5.0
2004-03-03 CVE-2004-0097 Unspecified vulnerability in Openh323 Project Pwlib
Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
network
low complexity
openh323-project
critical
10.0