CVE-2012-1008
medium · 5OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.
5
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2012-02-08
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| officesip | officesip_server | 3.1 |
Check a specific version with /api/v1/cve/match.
References
- http://secpod.org/advisories/SecPod_Exploit_OfficeSIP_Server_DOS_Vuln.txt
- http://secpod.org/blog/?p=461
- http://secpod.org/exploits/SecPod_Exploit_OfficeSIP_Server_DOS.py
- http://www.exploit-db.com/exploits/18453
- http://secpod.org/advisories/SecPod_Exploit_OfficeSIP_Server_DOS_Vuln.txt
- http://secpod.org/blog/?p=461
- http://secpod.org/exploits/SecPod_Exploit_OfficeSIP_Server_DOS.py
- http://www.exploit-db.com/exploits/18453
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-1008