Communications Webrtc Session Controller

Vendor:

First CVE: Jan 28, 2015 · Active for 11 years

17
Total CVEs
More Total CVEs than 93% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Communications Webrtc Session Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 28, 2015
11 years ago
Most Recent CVE
Dec 18, 2021
1,682 days ago

CVE Severity & Scoring

Communications Webrtc Session Controller17 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (94.1%)
Unknown1 (5.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (82.4%)
High2 (11.8%)
Unknown1 (5.9%)
User Interaction
None12 (70.6%)
Unknown1 (5.9%)
Required4 (23.5%)
Privileges Required
Low1 (5.9%)
High0 (0.0%)
None15 (88.2%)
Unknown1 (5.9%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code
Jan 28, 201510.092NOYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no
May 24, 20189.839NONO
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused
Dec 6, 20155.339NONO
A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
Mar 14, 20189.837NONO
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses
Jan 18, 20186.134NONO
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Cl
Jul 9, 20189.832NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.9% of CVEs· 97th percentile
Nuclei
1 CVE
5.9% of CVEs· 97th percentile
ExploitDB
3 CVEs
17.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Communications Webrtc Session Controller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.2.126.051.1%00
7.2.0.015.9100.0%00
7.2.016.12.2%00
7.267.160.7%03
7.137.245.1%01
7.037.245.1%01