Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-42225 is a high-severity vulnerability in the pjsip pjproject library prior to version 2.17. On GnuTLS builds, the SIP TLS transport component can accept connections with invalid or untrusted certificates even when certificate verification is explicitly enabled. This improper certificate validation issue is identified as CWE-295. The vulnerability has been patched in version 2.17. No known exploits in the wild have been reported. Join the discussion | CVE Database V5 | 05/07/2026, 18:47:26 UTC Added: 05/07/2026, 19:22:02 UTC |
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17. Join the discussion | CVE Database V5 | 04/24/2026, 18:40:08 UTC Added: 04/24/2026, 18:51:19 UTC |
CVE-2026-41415 is an out-of-bounds read vulnerability in the pjsip pjproject library versions 2.16 and earlier. It occurs when parsing a malformed Content-ID URI in a SIP multipart message body due to insufficient length validation, allowing reads beyond buffer boundaries. This vulnerability has a medium severity with a CVSS score of 6.7. The issue is fixed in version 2.17 of pjproject. Join the discussion | CVE Database V5 | 04/24/2026, 18:38:36 UTC Added: 04/24/2026, 18:51:19 UTC |
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in PJSIP when using pre-computed digest credentials (PJSIP_CRED_DATA_DIGEST). The function copies credential data using cred_info->data.slen as the length without an upper-bound check, which can overflow the fixed-size ha1 stack buffer (128 bytes) if data.slen exceeds the expected digest string length. Join the discussion | CVE Database V5 | 04/21/2026, 19:55:26 UTC Added: 04/21/2026, 20:46:07 UTC |
CVE-2026-40614 is a heap-based buffer overflow vulnerability in the pjsip pjproject library versions 2.16 and earlier. It arises from insufficient buffer size validation when decoding Opus audio frames, where the allocated buffer is smaller than the maximum possible encoded frame size. This causes unsafe memory copying operations leading to a heap overflow. The vulnerability has a high severity with a CVSS score of 8.5. No official patch or remediation guidance is currently available from the vendor. Join the discussion | CVE Database V5 | 04/21/2026, 18:04:15 UTC Added: 04/21/2026, 18:46:06 UTC |
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability Structure (SS) data. Insufficient bounds checking on the payload descriptor length may cause reads beyond the allocated RTP payload buffer. This issue has been patched in version 2.17. A workaround for this issue involves disabling VP9 codec if not needed. Join the discussion | CVE Database V5 | 03/31/2026, 15:36:47 UTC Added: 03/31/2026, 15:53:22 UTC |
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past the delimiter without verifying it has not reached the buffer end. This allows 1-2 bytes of adjacent heap memory to be read. All applications that process incoming SIP messages with multipart bodies or SDP content are potentially affected. This issue is resolved in version 2.17. Join the discussion | CVE Database V5 | 03/20/2026, 08:21:51 UTC Added: 03/20/2026, 15:54:21 UTC |
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's built-in DNS resolver, such as those configured with pjsua_config.nameserver or UaConfig.nameserver in PJSUA/PJSUA2. It does not affect users who rely on the OS resolver (e.g., getaddrinfo()) by not configuring a nameserver, or those using an external resolver via pjsip_resolver_set_ext_resolver(). This issue is fixed in version 2.17. For users unable to upgrade, a workaround is to disable DNS resolution in the PJSIP config (by setting nameserver_count to zero) or to use an external resolver implementation instead. Join the discussion | CVE Database V5 | 03/20/2026, 03:54:00 UTC Added: 03/20/2026, 04:09:23 UTC |
0 CVE-2026-32942 is a high-severity use-after-free vulnerability in the pjsip pjproject multimedia communication library, affecting versions prior to 2.17. The flaw arises from race conditions during ICE session destruction and callback execution, leading to heap memory corruption. Exploitation requires no authentication or user interaction and can result in high confidentiality and integrity impacts, such as remote code execution or denial of service. The vulnerability has been fixed in version 2.17. Organizations using vulnerable versions of pjproject in VoIP or multimedia applications should urgently update to mitigate risks. No known exploits are currently reported in the wild. Countries with significant pjproject deployment and strategic VoIP infrastructure are at higher risk. Join the discussion | CVE Database V5 | 03/20/2026, 03:43:37 UTC Added: 03/20/2026, 04:09:23 UTC |
0 PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17. Join the discussion | CVE Database V5 | 03/06/2026, 06:36:55 UTC Added: 03/06/2026, 07:01:04 UTC |
Showing 1 to 10 of 13 results