Vulnerability index

Browse CVEs

83 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Source HIGH 7.5
CVE-2017-9372

PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, a…

Mitigation only
Fix from $1,950 2017-06-02
Open Source HIGH 7.5
CVE-2017-9359

The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.1…

Mitigation only
Fix from $1,950 2017-06-02
Asterisk HIGH 8.8
CVE-2017-7617EPSS 6%

Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 be…

Fix: after 13.13-cert2
Fix from $1,950 2017-04-10
Asterisk MEDIUM 5.3
CVE-2016-9938

An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 1…

Mitigation only
Fix from $1,600 2016-12-12
Asterisk HIGH 7.5
CVE-2016-9937

An issue was discovered in Asterisk Open Source 13.12.x and 13.13.x before 13.13.1 and 14.x before 14.2.1. If an SDP offer or answer is received with…

Patch available
Fix from $1,950 2016-12-12
Asterisk MEDIUM 6.5
CVE-2016-2232EPSS 5%

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before…

Mitigation only
Fix from $1,600 2016-02-22
Certified Asterisk MEDIUM 5.0
CVE-2014-9374EPSS 10%

Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13…

Patch available
Fix from $1,600 2014-12-12
Certified Asterisk HIGH 9.0
CVE-2014-8418

The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified …

Fix: 11.14.1 / 12.7.1+
Fix from $1,950 2014-11-24
Asterisk MEDIUM 6.5
CVE-2014-8417

ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote au…

Fix: 11.14.1 / 12.7.1+
Fix from $1,600 2014-11-24
Asterisk MEDIUM 5.0
CVE-2014-8416

Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_…

Fix: 12.7.1 / 13.0.1+
Fix from $1,600 2014-11-24
Asterisk MEDIUM 5.0
CVE-2014-8415

Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a …

Fix: 12.7.1 / 13.0.1+
Fix from $1,600 2014-11-24
Asterisk MEDIUM 5.0
CVE-2014-8414

ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote …

Fix: after 11.14.0
Fix from $1,600 2014-11-24
Asterisk HIGH 7.5
CVE-2014-8413

The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and load ACLs defined in pjsip.co…

Fix: 12.7.1 / 13.0.1+
Fix from $1,950 2014-11-24
Certified Asterisk MEDIUM 5.0
CVE-2014-8412

The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1,…

Fix: 1.8.32.1 / 11.14.1+
Fix from $1,600 2014-11-24
Asterisk MEDIUM 6.5
CVE-2014-4046EPSS 6%

Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager use…

Patch available
Fix from $1,600 2014-06-17
Certified Asterisk MEDIUM 5.0
CVE-2014-4047

Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 be…

Patch available
Fix from $1,600 2014-06-17
Asterisk MEDIUM 5.0
CVE-2013-7100

Buffer overflow in the unpacksms16 function in apps/app_sms.c in Asterisk Open Source 1.8.x before 1.8.24.1, 10.x before 10.12.4, and 11.x before 11.…

Patch available
Fix from $1,600 2013-12-19
Asterisk MEDIUM 5.0
CVE-2013-5641

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.17.x through 1.8.22.x, 1.8.23.x before 1.8.23.1, and 11.x before 11.5.1 and …

Patch available
Fix from $1,600 2013-09-09
Asterisk MEDIUM 5.0
CVE-2013-5642EPSS 12%

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified As…

Patch available
Fix from $1,600 2013-09-09
Asterisk MEDIUM 5.0
CVE-2012-5976

Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Aste…

Fix: after 1.8.19.0
Fix from $1,600 2013-01-04
Asterisk HIGH 7.5
CVE-2012-1184EPSS 16%

Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote a…

Patch available
Fix from $1,950 2012-09-18
Asterisk MEDIUM 6.0
CVE-2012-4737

channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Di…

Mitigation only
Fix from $1,600 2012-08-31
Asterisk MEDIUM 5.0
CVE-2011-4597

The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numb…

Mitigation only
Fix from $1,600 2011-12-15
Asterisk MEDIUM 5.0
CVE-2011-2529

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' character…

Patch available
Fix from $1,600 2011-07-06
Asterisk MEDIUM 5.0
CVE-2011-2535

chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asteri…

Patch available
Fix from $1,600 2011-07-06
Asterisk MEDIUM 5.0
CVE-2011-2536

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk…

Patch available
Fix from $1,600 2011-07-06
Asterisk MEDIUM 5.0
CVE-2011-2665

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.3 allows remote attackers to cause a denial of service (NULL po…

Patch available
Fix from $1,600 2011-07-06
Asterisk MEDIUM 5.0
CVE-2011-2666

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the…

No fix yet
Fix from $1,600 2011-07-06
Asterisk MEDIUM 5.0
CVE-2011-2216

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote atta…

Mitigation only
Fix from $1,600 2011-06-06
Asterisk HIGH 9.0
CVE-2011-1599

manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x befor…

Mitigation only
Fix from $1,950 2011-04-27