Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Asterisk HIGH 8.8
CVE-2024-42365

Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-…

Fix: 18.24.2 / 20.9.1+
Fix from $1,950 2024-08-08
Open Source MEDIUM 5.0
CVE-2013-2686

main/http.c in the HTTP server in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 …

Mitigation only
Fix from $1,600 2013-04-01
Open Source HIGH 7.5
CVE-2013-2685

Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-04-01
Open Source MEDIUM 5.0
CVE-2013-2264

The SIP channel driver in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1…

Mitigation only
Fix from $1,600 2013-04-01
Open Source HIGH 9.0
CVE-2012-2186

Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 …

Fix: after 10.7.0
Fix from $1,950 2012-08-31
Open Source MEDIUM 6.5
CVE-2012-2414

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk B…

Patch available
Fix from $1,600 2012-04-30
Open Source MEDIUM 6.5
CVE-2012-2415

Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and …

Patch available
Fix from $1,600 2012-04-30
Open Source MEDIUM 6.5
CVE-2012-2416

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before …

Patch available
Fix from $1,600 2012-04-30
Open Source MEDIUM 6.8
CVE-2011-4063

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables d…

Mitigation only
Fix from $1,600 2011-10-21
Asterisk MEDIUM 5.0
CVE-2010-0441

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows re…

Patch available
Fix from $1,600 2010-02-04
Asterisk HIGH 7.8
CVE-2009-2346

The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.…

Mitigation only
Fix from $1,950 2009-09-08
Asterisk Business Edition MEDIUM 5.0
CVE-2009-0041

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7…

Fix: after 1.6.0.3
Fix from $1,600 2009-01-14
Zaptel HIGH 7.2
CVE-2008-5744

Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer…

Fix: after 1.4.11
Fix from $1,950 2008-12-26
Zaptel HIGH 7.2
CVE-2008-5396

Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group t…

Fix: after 1.4.11
Fix from $1,950 2008-12-09
Asterisk Appliance Developer Kit HIGH 7.8
CVE-2008-3264

The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B…

Mitigation only
Fix from $1,950 2008-07-24
Asterisk HIGH 7.8
CVE-2008-3263EPSS 28%

The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before …

No fix yet
Fix from $1,950 2008-07-22
Asterisk Addons MEDIUM 5.0
CVE-2008-2543

The ooh323 channel driver in Asterisk Addons 1.2.x before 1.2.9 and Asterisk-Addons 1.4.x before 1.4.7 creates a remotely accessible TCP port that is…

Mitigation only
Fix from $1,600 2008-06-05
Asterisk Appliance Developer Kit HIGH 7.1
CVE-2008-1923

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated cal…

Fix: after 1.1.0.2
Fix from $1,950 2008-04-23
Asterisk HIGH 9.3
CVE-2008-1390

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, Asteri…

Mitigation only
Fix from $1,950 2008-03-24
Asterisk Appliance Developer Kit HIGH 7.5
CVE-2008-1289EPSS 12%

Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x …

Fix: after 1.6.0_beta5
Fix from $1,950 2008-03-24
Asterisk HIGH 8.8
CVE-2008-1332

Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2…

Fix: after 1.4.19
Fix from $1,950 2008-03-20
Open Source MEDIUM 5.8
CVE-2008-1333

Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messa…

Patch available
Fix from $1,600 2008-03-20
Asterisk Appliance Developer Kit MEDIUM 5.0
CVE-2008-0095EPSS 25%

The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Develope…

Fix: after 1.4.16
Fix from $1,600 2008-01-08
Asterisk Addons HIGH 7.5
CVE-2007-5488

Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute …

Fix: after 1.4.3
Fix from $1,950 2007-10-17
Asterisk MEDIUM 5.0
CVE-2007-4521

Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2007-08-28
Asterisk MEDIUM 5.0
CVE-2007-4455

The SIP channel driver (chan_sip) in Asterisk Open Source 1.4.x before 1.4.11, AsteriskNOW before beta7, Asterisk Appliance Developer Kit 0.x before …

Fix: after 1.4.9
Fix from $1,600 2007-08-22
Asterisk HIGH 9.3
CVE-2007-3762EPSS 6%

Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1,…

Fix: after 0.4
Fix from $1,950 2007-07-18
Asterisk MEDIUM 5.0
CVE-2007-3763EPSS 27%

The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appl…

Fix: after 0.4
Fix from $1,600 2007-07-18
Asterisk MEDIUM 5.0
CVE-2007-3764EPSS 32%

The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, …

Fix: after 0.4
Fix from $1,600 2007-07-18
Asterisk MEDIUM 5.0
CVE-2007-3765

The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows…

Fix: after 0.4
Fix from $1,600 2007-07-18