Ekiga is a niche voice-over-IP and videoconferencing application whose vulnerability footprint centers on a single product with a history of input-handling and memory-safety issues including improper input validation, code injection, buffer-boundary violations, and format-string weaknesses. Vulnerabilities affecting this vendor have frequently acquired public exploit code, reflecting the accessibility of network-facing parsing logic in VoIP implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ekiga over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4924MEDIUM The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an inv | Oct 8, 2007 | 5.0 | 28 | NO | YES |
CVE-2011-1830HIGH Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so. | Apr 22, 2019 | 8.8 | 27 | NO | NO |
CVE-2007-4897MEDIUM pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (application crash) via a long argument to the PString::vsprintf fun | Sep 14, 2007 | 5.0 | 27 | NO | YES |
CVE-2007-1007HIGH Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in | Feb 20, 2007 | 10.0 | 27 | NO | NO |
CVE-2007-1006HIGH Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrar | Feb 20, 2007 | 10.0 | 25 | NO | NO |
CVE-2012-5621MEDIUM lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains i | Sep 29, 2014 | 5.0 | 20 | NO | NO |
CVE-2013-1864MEDIUM The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to ca | May 23, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ekiga.
Media articles that mention a CVE ID that affects a product developed by Ekiga — matched by CVE ID, not by vendor name.