Digium
digium
119 CVEs • 12 products
Products (12)
Click to collapseToggle
Products (12)
Click to collapse
CVEs (119)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario. |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Jul 12, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP neg...Show more |
1Digium 2Asterisk Certified AsteriskJun 17, 2026 Jul 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message. |
asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote). |
An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially cr...Show more |
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Sep 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxNov 21, 2024 Jun 12, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specif...Show more |
An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop). |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Feb 22, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation f...Show more |
A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs and desired payload numbers. While an SDP negotiation may result in a c...Show more |
2Debian Digium3Asterisk Certified AsteriskDebian LinuxJun 17, 2026 Feb 22, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub modu...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Dec 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact he...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Dec 13, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RT...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Dec 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel dri...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Nov 9, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is cre...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Nov 9, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user fie...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffe...Show more |
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injection vulnerability has been identified that may allow the execution of...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Sep 2, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module h...Show more |