SIPp is a test tool for Session Initiation Protocol traffic generation and validation, presenting a narrowly scoped product footprint focused on telecommunications and VoIP infrastructure testing. Its observed vulnerabilities cluster around missing authentication protections for critical functionality, which represents the primary exposure class affecting this project. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sipp Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25356HIGH SIPp 3.6 and earlier contains a local buffer overflow vulnerability in command-line argument handling that allows local attackers to crash the application or execute arbitrary code | May 23, 2026 | 8.4 | 33 | NO | NO |
CVE-2018-25225HIGH SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuratio | Mar 28, 2026 | 8.4 | 28 | NO | NO |
CVE-2008-1959HIGH Stack-based buffer overflow in the get_remote_video_port_media function in call.cpp in SIPp 3.0 allows remote attackers to cause a denial of service and possibly execute arbitrary | Apr 25, 2008 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sipp Project.
Media articles that mention a CVE ID that affects a product developed by Sipp Project — matched by CVE ID, not by vendor name.