Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Asterisk HIGH 7.5
CVE-2016-7550

asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

No fix yet
Fix from $1,950 2019-05-23
Asterisk MEDIUM 5.9
CVE-2018-7287EPSS 11%

An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket paylo…

Mitigation only
Fix from $1,600 2018-02-22
Asterisk HIGH 7.5
CVE-2017-14603

In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cer…

Mitigation only
Fix from $1,950 2017-10-10
Open Source HIGH 7.5
CVE-2017-9372

PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, a…

Mitigation only
Fix from $1,950 2017-06-02
Open Source HIGH 7.5
CVE-2017-9359

The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.1…

Mitigation only
Fix from $1,950 2017-06-02
Asterisk MEDIUM 5.3
CVE-2016-9938

An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 1…

Mitigation only
Fix from $1,600 2016-12-12
Asterisk MEDIUM 6.5
CVE-2016-2232EPSS 5%

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before…

Mitigation only
Fix from $1,600 2016-02-22
Asterisk MEDIUM 6.0
CVE-2012-4737

channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Di…

Mitigation only
Fix from $1,600 2012-08-31
Asterisk MEDIUM 5.0
CVE-2011-4597

The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numb…

Mitigation only
Fix from $1,600 2011-12-15
Asterisk MEDIUM 5.0
CVE-2011-2666

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the…

No fix yet
Fix from $1,600 2011-07-06
Asterisk MEDIUM 5.0
CVE-2011-2216

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote atta…

Mitigation only
Fix from $1,600 2011-06-06
Asterisk HIGH 9.0
CVE-2011-1599

manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x befor…

Mitigation only
Fix from $1,950 2011-04-27
Asterisk MEDIUM 5.0
CVE-2011-1174

manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2011-03-31
Asterisk MEDIUM 5.0
CVE-2010-0685

The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using t…

No fix yet
Fix from $1,600 2010-02-23
Asterisk MEDIUM 5.0
CVE-2009-4055

rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition B.x.…

No fix yet
Fix from $1,600 2009-12-02
Asterisk HIGH 7.8
CVE-2007-1306EPSS 20%

Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol…

Mitigation only
Fix from $1,950 2007-03-07
Asterisk MEDIUM 5.0
CVE-2005-3559EPSS 20%

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) i…

No fix yet
Fix from $1,600 2005-11-16
Asterisk MEDIUM 5.0
CVE-2005-2081

Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attac…

Mitigation only
Fix from $1,600 2005-07-05
Asterisk HIGH 7.5
CVE-2003-0779

SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a…

No fix yet
Fix from $1,950 2003-09-22
Asterisk HIGH 7.5
CVE-2003-0761

Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before Augus…

No fix yet
Fix from $1,950 2003-09-17