freeswitch kayıtları
freeswitch üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %4,8
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %71,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication4
- CWE-20 Improper Input Validation3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-703 Improper Check or Handling of Exceptional Conditions1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2019-19492Silahlaştırılmış | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.freeswitch · freeswitch · CWE-798 | Kritik9,8 | — | %29,4 | 1 Ara 2019 |
39İzleyin | CVE-2026-49841İstismar yok | FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body readfreeswitch · freeswitch · CWE-122 | Kritik9,8 | — | %0,6 | 9 Haz 2026 |
36İzleyin | CVE-2026-49840İstismar yok | FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsingfreeswitch · freeswitch · CWE-20 | Kritik9,1 | — | %0,5 | 9 Haz 2026 |
31İzleyin | CVE-2015-7392İstismar yok | Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allowsfreeswitch · freeswitch · CWE-119 | Yüksek7,5 | — | %4,7 | 5 Eki 2015 |
31İzleyin | CVE-2021-37624Kavram kanıtı | FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofingfreeswitch · freeswitch · CWE-287 | Yüksek7,5 | — | %3,7 | 25 Eki 2021 |
31İzleyin | CVE-2018-19911Kavram kanıtı | FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/syfreeswitch · freeswitch · CWE-77 | Yüksek7,5 | — | %2,7 | 6 Ara 2018 |
31İzleyin | CVE-2021-41105İstismar yok | FreeSWITCH susceptible to Denial of Service via invalid SRTP packetsfreeswitch · freeswitch · CWE-20 | Yüksek7,5 | — | %2,5 | 25 Eki 2021 |
30İzleyin | CVE-2021-41145İstismar yok | FreeSWITCH susceptible to Denial of Service via SIP floodingfreeswitch · freeswitch · CWE-400 | Yüksek7,5 | — | %1,7 | 25 Eki 2021 |
30İzleyin | CVE-2023-40018İstismar yok | FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component IDfreeswitch · freeswitch · CWE-787 | Yüksek7,5 | — | %1,0 | 15 Eyl 2023 |
30İzleyin | CVE-2021-41158İstismar yok | FreeSWITCH vulnerable to SIP digest leak for configured gatewaysfreeswitch · freeswitch · CWE-200 | Yüksek7,5 | — | %0,8 | 26 Eki 2021 |
30İzleyin | CVE-2026-49842İstismar yok | FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test framesfreeswitch · freeswitch · CWE-400 | Yüksek7,5 | — | %0,6 | 9 Haz 2026 |
30İzleyin | CVE-2026-49847İstismar yok | FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSONfreeswitch · freeswitch · CWE-674 | Yüksek7,5 | — | %0,5 | 9 Haz 2026 |
30İzleyin | CVE-2026-49475İstismar yok | FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsingfreeswitch · freeswitch · CWE-20 | Yüksek7,5 | — | %0,5 | 9 Haz 2026 |
30İzleyin | CVE-2026-45771İstismar yok | Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansionfreeswitch · freeswitch · CWE-776 | Yüksek7,5 | — | %0,5 | 9 Haz 2026 |
28İzleyin | CVE-2013-2238İstismar yok | Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a freeswitch · freeswitch · CWE-119 | Orta6,8 | — | %2,7 | 30 Eyl 2013 |
26İzleyin | CVE-2023-40019İstismar yok | FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec namesfreeswitch · freeswitch · CWE-770 | Orta6,5 | — | %0,9 | 15 Eyl 2023 |
23İzleyin | CVE-2023-51443İstismar yok | FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiationfreeswitch · freeswitch · CWE-703 | Orta5,9 | — | %1,5 | 27 Ara 2023 |
22İzleyin | CVE-2021-41157İstismar yok | FreeSWITCH does not authenticate SIP SUBSCRIBE requests by defaultfreeswitch · freeswitch · CWE-287 | Orta5,3 | — | %1,7 | 26 Eki 2021 |
21İzleyin | CVE-2026-49843İstismar yok | FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`freeswitch · freeswitch · CWE-287 | Orta5,3 | — | %0,5 | 9 Haz 2026 |
21İzleyin | CVE-2026-49472İstismar yok | FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpatfreeswitch · freeswitch · CWE-116 | Orta5,3 | — | %0,4 | 9 Haz 2026 |
17İzleyin | CVE-2026-49848İstismar yok | FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`freeswitch · freeswitch · CWE-287 | Orta4,3 | — | %0,3 | 9 Haz 2026 |
- CVE-2019-1949248Planlayın
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
KritikCVSS 9,8SilahlaştırılmışEPSS %29freeswitch · freeswitch1 Ara 2019
- CVE-2026-4984139İzleyin
FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
KritikCVSS 9,8İstismar yokEPSS %1freeswitch · freeswitch9 Haz 2026
- CVE-2026-4984036İzleyin
FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
KritikCVSS 9,1İstismar yokEPSS %0freeswitch · freeswitch9 Haz 2026
- CVE-2015-739231İzleyin
Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows
YüksekCVSS 7,5İstismar yokEPSS %5freeswitch · freeswitch5 Eki 2015
- CVE-2021-3762431İzleyin
FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing
YüksekCVSS 7,5Kavram kanıtıEPSS %4freeswitch · freeswitch25 Eki 2021
- CVE-2018-1991131İzleyin
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/sy
YüksekCVSS 7,5Kavram kanıtıEPSS %3freeswitch · freeswitch6 Ara 2018
- CVE-2021-4110531İzleyin
FreeSWITCH susceptible to Denial of Service via invalid SRTP packets
YüksekCVSS 7,5İstismar yokEPSS %3freeswitch · freeswitch25 Eki 2021
- CVE-2021-4114530İzleyin
FreeSWITCH susceptible to Denial of Service via SIP flooding
YüksekCVSS 7,5İstismar yokEPSS %2freeswitch · freeswitch25 Eki 2021
- CVE-2023-4001830İzleyin
FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID
YüksekCVSS 7,5İstismar yokEPSS %1freeswitch · freeswitch15 Eyl 2023
- CVE-2021-4115830İzleyin
FreeSWITCH vulnerable to SIP digest leak for configured gateways
YüksekCVSS 7,5İstismar yokEPSS %1freeswitch · freeswitch26 Eki 2021
- CVE-2026-4984230İzleyin
FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames
YüksekCVSS 7,5İstismar yokEPSS %1freeswitch · freeswitch9 Haz 2026
- CVE-2026-4984730İzleyin
FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
YüksekCVSS 7,5İstismar yokEPSS %1freeswitch · freeswitch9 Haz 2026
- CVE-2026-4947530İzleyin
FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing
YüksekCVSS 7,5İstismar yokEPSS %0freeswitch · freeswitch9 Haz 2026
- CVE-2026-4577130İzleyin
Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
YüksekCVSS 7,5İstismar yokEPSS %0freeswitch · freeswitch9 Haz 2026
- CVE-2013-223828İzleyin
Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a
OrtaCVSS 6,8İstismar yokEPSS %3freeswitch · freeswitch30 Eyl 2013
- CVE-2023-4001926İzleyin
FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names
OrtaCVSS 6,5İstismar yokEPSS %1freeswitch · freeswitch15 Eyl 2023
- CVE-2023-5144323İzleyin
FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation
OrtaCVSS 5,9İstismar yokEPSS %1freeswitch · freeswitch27 Ara 2023
- CVE-2021-4115722İzleyin
FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default
OrtaCVSS 5,3İstismar yokEPSS %2freeswitch · freeswitch26 Eki 2021
- CVE-2026-4984321İzleyin
FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`
OrtaCVSS 5,3İstismar yokEPSS %1freeswitch · freeswitch9 Haz 2026
- CVE-2026-4947221İzleyin
FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat
OrtaCVSS 5,3İstismar yokEPSS %0freeswitch · freeswitch9 Haz 2026
- CVE-2026-4984817İzleyin
FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`
OrtaCVSS 4,3İstismar yokEPSS %0freeswitch · freeswitch9 Haz 2026