Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Asterisk HIGH 10.0
CVE-2007-2488

The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss …

Fix: after 1.4.4_2007-04-27
Fix from $1,950 2007-05-07
Asterisk HIGH 7.8
CVE-2007-2294

The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 auth…

Patch available
Fix from $1,950 2007-04-26
Asterisk HIGH 7.8
CVE-2007-2297

The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a vali…

Patch available
Fix from $1,950 2007-04-26
Asterisk HIGH 7.6
CVE-2007-2293EPSS 24%

Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow rem…

Patch available
Fix from $1,950 2007-04-26
Asterisk HIGH 7.8
CVE-2007-1594

The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (cra…

Patch available
Fix from $1,950 2007-03-22
Asterisk HIGH 7.5
CVE-2007-1595

The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute ar…

Patch available
Fix from $1,950 2007-03-22
Asterisk HIGH 7.8
CVE-2007-1561EPSS 14%

The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE mes…

Patch available
Fix from $1,950 2007-03-21