CVEs (114)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Digium Sangoma2Asterisk Certified AsteriskJun 17, 2026 Dec 14, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due...Show more |
2Digium Sangoma2Asterisk Certified AsteriskJun 17, 2026 Dec 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary...Show more |
2Digium Sangoma2Asterisk Certified AsteriskJun 17, 2026 Dec 14, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionali...Show more |
3Asterisk DebianDigium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Aug 30, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Apr 15, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in...Show more |
2Debian Digium2Asterisk Debian LinuxJun 17, 2026 Apr 15, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2...Show more |
2Debian Digium2Asterisk Debian LinuxJun 17, 2026 Apr 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Re...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Jul 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet th...Show more |
An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a BYE request. |
1Digium 2Asterisk Certified AsteriskJun 17, 2026 Feb 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause a...Show more |
1Digium 2Asterisk Certified AsteriskJun 17, 2026 Feb 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replayin...Show more |
1Digium 2Asterisk Certified AsteriskJun 17, 2026 Feb 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP neg...Show more |
1Digium 2Asterisk Certified AsteriskJun 17, 2026 Feb 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delay...Show more |
A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses. |
An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message is received with a H...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Nov 22, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorizatio...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Nov 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL p...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that ca...Show more |
res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs bec...Show more |
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario. |