Vulnerability index

Browse CVEs

83 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Asterisk MEDIUM 5.0
CVE-2011-1507

Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Editio…

Patch available
Fix from $1,600 2011-04-27
Asterisk MEDIUM 5.0
CVE-2011-1174

manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2011-03-31
Asterisk MEDIUM 5.0
CVE-2011-1175

tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1.x before 1.6.1.23, 1.6.2.x before 1.6.2.17.1, and 1.8.x before 1.8.3.1 allows remote att…

Patch available
Fix from $1,600 2011-03-31
Asterisk MEDIUM 6.8
CVE-2011-1147

Multiple stack-based and heap-based buffer overflows in the (1) decode_open_type and (2) udptl_rx_packet functions in main/udptl.c in Asterisk Open S…

Patch available
Fix from $1,600 2011-03-15
Asterisk MEDIUM 5.0
CVE-2010-0685

The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using t…

No fix yet
Fix from $1,600 2010-02-23
Asterisk MEDIUM 5.0
CVE-2009-4055

rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition B.x.…

No fix yet
Fix from $1,600 2009-12-02
Asterisk MEDIUM 5.0
CVE-2009-3727

Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x b…

Patch available
Fix from $1,600 2009-11-10
Asterisk HIGH 7.8
CVE-2009-2726EPSS 7%

The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Aster…

Fix: 1.2.34 / 1.3.0.3+
Fix from $1,950 2009-08-12
Asterisk MEDIUM 5.0
CVE-2009-2651

main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a …

Patch available
Fix from $1,600 2009-07-30
Asterisk HIGH 7.5
CVE-2007-6171

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remo…

Fix: 1.4.15+
Fix from $1,950 2007-11-30
Asterisk MEDIUM 6.8
CVE-2007-5358

Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers t…

Fix: after 1.4.12
Fix from $1,600 2007-10-12
Asterisk HIGH 7.5
CVE-2007-4103EPSS 6%

The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and Asterisk Appliance Developer Kit before 0.6.0, when…

Fix: 0.6.0 / 1.2.23+
Fix from $1,950 2007-07-31
Asterisk HIGH 7.8
CVE-2007-1306EPSS 20%

Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol…

Mitigation only
Fix from $1,950 2007-03-07
Asterisk HIGH 7.8
CVE-2006-5445

Unspecified vulnerability in the SIP channel driver (channels/chan_sip.c) in Asterisk 1.2.x before 1.2.13 and 1.4.x before 1.4.0-beta3 allows remote …

Patch available
Fix from $1,950 2006-10-23
Asterisk HIGH 7.5
CVE-2006-5444EPSS 85%

Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as u…

Patch available
Fix from $1,950 2006-10-23
Asterisk HIGH 7.5
CVE-2006-4345EPSS 8%

Stack-based buffer overflow in channels/chan_mgcp.c in MGCP in Asterisk 1.0 through 1.2.10 allows remote attackers to execute arbitrary code via a cr…

Patch available
Fix from $1,950 2006-08-24
Asterisk HIGH 7.5
CVE-2006-4346EPSS 7%

Asterisk 1.2.10 supports the use of client-controlled variables to determine filenames in the Record function, which allows remote attackers to (1) e…

Patch available
Fix from $1,950 2006-08-24
Asterisk HIGH 7.5
CVE-2006-2898

The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and 1.0.x before 1.0.11 allows remote attackers to cause a denial of service (cra…

Patch available
Fix from $1,950 2006-06-07
Asterisk MEDIUM 6.4
CVE-2006-1827EPSS 7%

Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that pas…

Fix: after 1.2.6
Fix from $1,600 2006-04-18
Asterisk MEDIUM 5.0
CVE-2005-3559EPSS 20%

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) i…

No fix yet
Fix from $1,600 2005-11-16
Asterisk MEDIUM 5.0
CVE-2005-2081

Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attac…

Mitigation only
Fix from $1,600 2005-07-05
Asterisk HIGH 7.5
CVE-2003-0779

SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a…

No fix yet
Fix from $1,950 2003-09-22
Asterisk HIGH 7.5
CVE-2003-0761

Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before Augus…

No fix yet
Fix from $1,950 2003-09-17