Vulnerabilities (CVE)

Filtered by vendor Meetecho Subscribe
Filtered by product Janus
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4124 1 Meetecho 1 Janus 2021-12-20 4.3 MEDIUM 6.1 MEDIUM
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4020 1 Meetecho 1 Janus 2021-11-30 3.5 LOW 5.4 MEDIUM
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-10575 1 Meetecho 1 Janus 2020-03-18 4.0 MEDIUM 4.2 MEDIUM
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times.
CVE-2020-10577 1 Meetecho 1 Janus 2020-03-17 5.8 MEDIUM 4.8 MEDIUM
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions.
CVE-2020-10576 1 Meetecho 1 Janus 2020-03-17 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash.