Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.2
CVE-2023-37457
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as we…
Asterisk
after 20.5.0
HIGH 7.5
CVE-2023-49294EPSS 46%
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certi…
Asterisk
18.20.1 / 20.5.1+
MEDIUM 5.9
CVE-2023-49786EPSS 5%
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certi…
Asterisk
18.20.1 / 20.5.1+
MEDIUM 6.5
CVE-2021-31878
An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk ha…
Asterisk
Patch available
MEDIUM 6.5
CVE-2021-26713
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Aste…
Asterisk
16.16.1 / 17.9.2+
HIGH 7.5
CVE-2021-26712
Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote una…
Asterisk
16.16.1 / 17.9.2+
HIGH 7.5
CVE-2021-26717
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6.…
Asterisk
16.16.1 / 17.9.2+
MEDIUM 6.5
CVE-2020-35776
A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk…
Asterisk
after 18.1.1
MEDIUM 5.9
CVE-2021-26906
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.…
Asterisk
13.38.2 / 16.16.1+
MEDIUM 6.5
CVE-2020-35652
An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x b…
Asterisk
13.38.0 / 16.15.0+
MEDIUM 5.3
CVE-2020-28327
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1…
Certified Asterisk
13.37.1 / 16.14.1+
MEDIUM 6.5
CVE-2019-15297
res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a r…
Asterisk
after 16.5.0
HIGH 7.5
CVE-2019-15639EPSS 22%
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a s…
Asterisk
after 16.5.0
MEDIUM 6.5
CVE-2019-12827
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users…
Asterisk
13.27.0 / 15.7.2+
HIGH 7.5
CVE-2016-7550
asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).
Asterisk
No fix yet
MEDIUM 6.5
CVE-2019-7251
An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier…
Asterisk
15.7.2 / 16.2.1+
HIGH 7.5
CVE-2018-19278
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk v…
Asterisk
Patch available
HIGH 7.5
CVE-2018-7285EPSS 5%
A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs …
Asterisk
after 15.2.1
MEDIUM 5.9
CVE-2018-7287EPSS 11%
An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket paylo…
Asterisk
Mitigation only
HIGH 7.5
CVE-2017-17850EPSS 75%
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages cr…
Asterisk
after 15.1.4
MEDIUM 5.9
CVE-2017-17664EPSS 32%
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk be…
Asterisk
13.18.4 / 14.7.4+
HIGH 7.5
CVE-2017-17090EPSS 82%
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13…
Certified Asterisk
after 15.1.2
HIGH 8.8
CVE-2017-16671
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13…
Asterisk
13.18.1 / 14.7.1+
MEDIUM 5.9
CVE-2017-16672
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-c…
Asterisk
13.18.1 / 14.7.1+
HIGH 7.5
CVE-2017-14603
In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cer…
Asterisk
Mitigation only
HIGH 8.8
CVE-2017-14001EPSS 6%
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injec…
Asterisk Gui
after 2.1.0
CRITICAL 9.8
CVE-2017-14100EPSS 15%
In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cer…
Asterisk
Patch available
HIGH 7.5
CVE-2017-14098EPSS 50%
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact…
Asterisk
Patch available
HIGH 7.5
CVE-2017-14099
In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17…
Asterisk
Patch available
MEDIUM 6.1
CVE-2015-2690
Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumaddoninstaller) before 2.11.0.7 …
Addons Module
Patch available