Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

Ekiga attempts to dlopen /tmp/ekiga_test.so

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.
0
Attacker Value
Unknown

CVE-2012-5621

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.
0
Attacker Value
Unknown

CVE-2013-1864

Disclosure Date: May 23, 2014 (last updated October 05, 2023)
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."
0
Attacker Value
Unknown

CVE-2007-4924

Disclosure Date: October 08, 2007 (last updated October 04, 2023)
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length header field in Session Initiation Protocol (SIP) packets, which causes a \0 byte to be written to an "attacker-controlled address."
0
Attacker Value
Unknown

CVE-2007-4897

Disclosure Date: September 14, 2007 (last updated October 04, 2023)
pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf function, related to a "memory management flaw". NOTE: this issue was originally reported as being in the SIPURL::GetHostAddress function in Ekiga (formerly GnomeMeeting).
0
Attacker Value
Unknown

CVE-2007-0999

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006.
0
Attacker Value
Unknown

CVE-2007-1007

Disclosure Date: February 20, 2007 (last updated October 04, 2023)
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.
0
Attacker Value
Unknown

CVE-2007-1006

Disclosure Date: February 20, 2007 (last updated October 04, 2023)
Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.
0