ekiga records
7 published records for vendor ekiga.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-399 Resource Management Errors1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2007-1007No exploit | Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execekiga · ekiga | Critical10.0 | — | 7.1% | Feb 20, 2007 |
41Plan | CVE-2007-1006No exploit | Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial ekiga · ekiga · CWE-134 | Critical10.0 | — | 3.7% | Feb 19, 2007 |
35Monitor | CVE-2011-1830No exploit | Ekiga attempts to dlopen /tmp/ekiga_test.soekiga · ekiga · CWE-94 | High8.8 | — | 0.8% | Apr 22, 2019 |
23Monitor | CVE-2007-4897Proof of concept | pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a loekiga · ekiga · CWE-399 | Medium5.0 | — | 10.9% | Sep 14, 2007 |
23Monitor | CVE-2007-4924Proof of concept | The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to causekiga · ekiga · CWE-20 | Medium5.0 | — | 10.7% | Oct 8, 2007 |
21Monitor | CVE-2012-5621No exploit | lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connekiga · ekiga · CWE-20 | Medium5.0 | — | 2.8% | Sep 29, 2014 |
18Monitor | CVE-2013-1864No exploit | The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansekiga · ekiga · CWE-119 | Medium4.3 | — | 2.9% | May 23, 2014 |
- CVE-2007-100742Plan
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly exec
CriticalCVSS 10.0No exploitEPSS 7%ekiga · ekigaFeb 20, 2007
- CVE-2007-100641Plan
Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial
CriticalCVSS 10.0No exploitEPSS 4%ekiga · ekigaFeb 19, 2007
- CVE-2011-183035Monitor
Ekiga attempts to dlopen /tmp/ekiga_test.so
HighCVSS 8.8No exploitEPSS 1%ekiga · ekigaApr 22, 2019
- CVE-2007-489723Monitor
pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a lo
MediumCVSS 5.0Proof of conceptEPSS 11%ekiga · ekigaSep 14, 2007
- CVE-2007-492423Monitor
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to caus
MediumCVSS 5.0Proof of conceptEPSS 11%ekiga · ekigaOct 8, 2007
- CVE-2012-562121Monitor
lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL conn
MediumCVSS 5.0No exploitEPSS 3%ekiga · ekigaSep 29, 2014
- CVE-2013-186418Monitor
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expans
MediumCVSS 4.3No exploitEPSS 3%ekiga · ekigaMay 23, 2014