Asterisk
asterisk
52 CVEs • 15 products
Products (15)
Click to collapseToggle
Products (15)
Click to collapse
CVEs (52)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to an incor...Show more |
1Asterisk 2Asterisk Business Edition Open SourceApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts in...Show more |
Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ct...Show more |
Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before...Show more |
1Asterisk 4Asterisk Appliance Developer Kit Asterisk Business EditionAsterisknow+1 moreApr 23, 2026 Jul 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance...Show more |
The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Ki...Show more |
The ooh323 channel driver in Asterisk Addons 1.2.x before 1.2.9 and Asterisk-Addons 1.4.x before 1.4.7 creates a remotely accessible TCP port that is intended solely for localhost communication, and interprets some TCP a...Show more |
1Asterisk 2Asterisk Business Edition Open SourceApr 23, 2026 Jun 4, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (da...Show more |
1Asterisk 5Asterisk Appliance Developer Kit Asterisk Business EditionAsterisknow+2 moreApr 23, 2026 Apr 23, 2008 N/A· v4 N/A· v3 7.1 HIGH· v2 The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW mes...Show more |
1Asterisk 5Asterisk Appliance Developer Kit Asterisk Business EditionAsterisknow+2 moreApr 23, 2026 Apr 23, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Applian...Show more |
1Asterisk 5Asterisk Asterisk Appliance Developer KitAsterisk Business Edition+2 moreApr 23, 2026 Mar 24, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and...Show more |
1Asterisk 5Asterisk Appliance Developer Kit Asterisk Business EditionAsterisknow+2 moreApr 23, 2026 Mar 24, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit...Show more |
Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API ca...Show more |
1Asterisk 6Asterisk Asterisk Appliance Developer KitAsterisk Business Edition+3 moreApr 23, 2026 Mar 20, 2008 N/A· v4 N/A· v3 8.8 HIGH· v2 Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Applian...Show more |
1Asterisk 5Asterisk Appliance Developer Kit Asterisk Business EditionAsterisknow+2 moreApr 23, 2026 Jan 8, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x bef...Show more |
1Asterisk 2Asterisk Business Edition Open SourceApr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication...Show more |
Buffer overflow in sethdlc.c in the Asterisk Zaptel 1.4.5.1 might allow local users to gain privileges via a long device name (interface name) in the ifr_name field. NOTE: the vendor disputes this issue, stating that th...Show more |
Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute arbitrary SQL commands via the (1) source and (2) destination numbers,...Show more |
Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which trigger...Show more |
1Asterisk 3Asterisk Asterisk Appliance Developer KitAsterisknowApr 23, 2026 Aug 22, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SIP channel driver (chan_sip) in Asterisk Open Source 1.4.x before 1.4.11, AsteriskNOW before beta7, Asterisk Appliance Developer Kit 0.x before 0.8.0, and s800i (Asterisk Appliance) 1.x before 1.0.3 allows remote at...Show more |