ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-4124
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NVD description · AI analysis pending
6.1<1% PoC
  • meetecho janus
CVE-2021-4020
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NVD description · AI analysis pending
5.4<1% PoC
  • meetecho janus
CVE-2020-14034
+1 in the same advisory: …14033
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0.

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

NVD description · AI analysis pending
9.82%
  • meetecho janus
CVE-2020-13901
+3 in the same advisory: …13898 …13900 …13899
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0.

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • meetecho janus
CVE-2020-10574
+4 in the same advisory: …10573 …10576 …10577 …10575
An issue was discovered in Janus through 0.9.1.

An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.

NVD description · AI analysis pending
9.8
group max
1%
  • meetecho janus