Resiprocate is a narrowly focused open-source SIP (Session Initiation Protocol) stack and communications library whose vulnerability surface reflects the parsing and protocol-handling demands of VoIP and real-time communications infrastructure. The observed weakness classes center on input validation, buffer-overflow conditions, out-of-bounds reads, and resource-consumption flaws that are characteristic of protocol parsers and network-facing C/C++ codebases. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Resiprocate over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12584CRITICAL The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) | Jul 16, 2018 | 9.8 | 55 | NO | YES |
CVE-2017-9454HIGH Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-rea | Aug 18, 2017 | 7.5 | 24 | NO | NO |
CVE-2008-3210MEDIUM rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a | Jul 18, 2008 | 5.0 | 23 | NO | YES |
CVE-2017-11521HIGH The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of service (memory consumption) by t | Jul 22, 2017 | 7.5 | 20 | NO | NO |
CVE-2008-3199HIGH Multiple unspecified vulnerabilities in ReSIProcate before 1.3.4 allow remote attackers to cause a denial of service (stack consumption) via unknown network traffic with a large "b | Jul 17, 2008 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Resiprocate.
Media articles that mention a CVE ID that affects a product developed by Resiprocate — matched by CVE ID, not by vendor name.