CVEs (51)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Apr 15, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Jul 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet th...Show more |
1Digium 2Asterisk Certified AsteriskNov 21, 2024 Feb 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause a...Show more |
1Digium 2Asterisk Certified AsteriskNov 21, 2024 Feb 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replayin...Show more |
1Digium 2Asterisk Certified AsteriskNov 21, 2024 Feb 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP neg...Show more |
1Digium 2Asterisk Certified AsteriskNov 21, 2024 Feb 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delay...Show more |
2Digium Sangoma2Asterisk Certified AsteriskNov 21, 2024 Nov 6, 2020 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP In...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Nov 22, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorizatio...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Nov 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL p...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that ca...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Jul 12, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP neg...Show more |
1Digium 2Asterisk Certified AsteriskNov 21, 2024 Jul 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message. |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Sep 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Jun 12, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specif...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Feb 22, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation f...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Feb 22, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub modu...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Dec 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact he...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Dec 13, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RT...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Dec 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel dri...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Nov 9, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is cre...Show more |