CVE detail
CVE-2025-12204
A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rvalue.c of the component Configuration File Handler. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This attack requires manipulating config files which might not be a realistic scenario in many cases. The vendor was contacted early about this disclosure but did not respond in any way.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://www.openwall.com/lists/oss-security/2025/10/27/8www.openwall.com
No excerpt available.
Exploitwww.openwall.comOct 27, 2025, 3:15 AM - http://www.openwall.com/lists/oss-security/2025/10/28/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comOct 27, 2025, 3:15 AM - http://www.openwall.com/lists/oss-security/2025/10/27/12www.openwall.com
No excerpt available.
Exploitwww.openwall.comOct 27, 2025, 3:15 AM - https://www.openwall.com/lists/oss-security/2025/11/02/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comOct 27, 2025, 3:15 AM - https://vuldb.com/?submit.673224vuldb.com
No excerpt available.
Exploitvuldb.comOct 27, 2025, 3:15 AM - https://vuldb.com/?id.329874vuldb.com
No excerpt available.
Exploitvuldb.comOct 27, 2025, 3:15 AM - https://vuldb.com/?ctiid.329874vuldb.com
No excerpt available.
Exploitvuldb.comOct 27, 2025, 3:15 AM No excerpt available.
Exploitshimo.imOct 27, 2025, 3:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-25583CVSS 7.8 · High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a h…
- CVE-2026-25582CVSS 7.8 · High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a h…
- CVE-2025-15537CVSS 1.9 · Low
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::string_value of the file plugins/input/shape/dbfile.cpp. Such m…
- CVE-2025-15536CVSS 1.9 · Low
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSegmentation of the file src/MaxMatchSegmentation.cpp. This ma…
- CVE-2026-0822CVSS 2.1 · Low
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based…
- CVE-2025-14958CVSS 1.9 · Low
A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library…