Vulnerability index

Browse CVEs

83 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Asterisk HIGH 8.2
CVE-2023-37457

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as we…

Fix: after 20.5.0
Fix from $1,950 2023-12-14
Asterisk HIGH 7.5
CVE-2023-49294EPSS 46%

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certi…

Fix: 18.20.1 / 20.5.1+
Fix from $1,950 2023-12-14
Asterisk MEDIUM 5.9
CVE-2023-49786EPSS 5%

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certi…

Fix: 18.20.1 / 20.5.1+
Fix from $1,600 2023-12-14
Asterisk MEDIUM 6.5
CVE-2021-31878

An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk ha…

Patch available
Fix from $1,600 2021-07-30
Asterisk MEDIUM 6.5
CVE-2021-26713

A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Aste…

Fix: 16.16.1 / 17.9.2+
Fix from $1,600 2021-02-19
Asterisk HIGH 7.5
CVE-2021-26712

Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote una…

Fix: 16.16.1 / 17.9.2+
Fix from $1,950 2021-02-18
Asterisk HIGH 7.5
CVE-2021-26717

An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6.…

Fix: 16.16.1 / 17.9.2+
Fix from $1,950 2021-02-18
Asterisk MEDIUM 6.5
CVE-2020-35776

A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk…

Fix: after 18.1.1
Fix from $1,600 2021-02-18
Asterisk MEDIUM 5.9
CVE-2021-26906

An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.…

Fix: 13.38.2 / 16.16.1+
Fix from $1,600 2021-02-18
Asterisk MEDIUM 6.5
CVE-2020-35652

An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x b…

Fix: 13.38.0 / 16.15.0+
Fix from $1,600 2021-01-29
Certified Asterisk MEDIUM 5.3
CVE-2020-28327

A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1…

Fix: 13.37.1 / 16.14.1+
Fix from $1,600 2020-11-06
Asterisk MEDIUM 6.5
CVE-2019-15297

res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a r…

Fix: after 16.5.0
Fix from $1,600 2019-09-09
Asterisk HIGH 7.5
CVE-2019-15639EPSS 22%

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a s…

Fix: after 16.5.0
Fix from $1,950 2019-09-09
Asterisk MEDIUM 6.5
CVE-2019-12827

Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users…

Fix: 13.27.0 / 15.7.2+
Fix from $1,600 2019-07-12
Asterisk HIGH 7.5
CVE-2016-7550

asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

No fix yet
Fix from $1,950 2019-05-23
Asterisk MEDIUM 6.5
CVE-2019-7251

An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier…

Fix: 15.7.2 / 16.2.1+
Fix from $1,600 2019-03-28
Asterisk HIGH 7.5
CVE-2018-19278

Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk v…

Patch available
Fix from $1,950 2018-11-14
Asterisk HIGH 7.5
CVE-2018-7285EPSS 5%

A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs …

Fix: after 15.2.1
Fix from $1,950 2018-02-22
Asterisk MEDIUM 5.9
CVE-2018-7287EPSS 11%

An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket paylo…

Mitigation only
Fix from $1,600 2018-02-22
Asterisk HIGH 7.5
CVE-2017-17850EPSS 75%

An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages cr…

Fix: after 15.1.4
Fix from $1,950 2017-12-27
Asterisk MEDIUM 5.9
CVE-2017-17664EPSS 32%

A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk be…

Fix: 13.18.4 / 14.7.4+
Fix from $1,600 2017-12-13
Certified Asterisk HIGH 7.5
CVE-2017-17090EPSS 82%

An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13…

Fix: after 15.1.2
Fix from $1,950 2017-12-02
Asterisk HIGH 8.8
CVE-2017-16671

A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13…

Fix: 13.18.1 / 14.7.1+
Fix from $1,950 2017-11-09
Asterisk MEDIUM 5.9
CVE-2017-16672

An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-c…

Fix: 13.18.1 / 14.7.1+
Fix from $1,600 2017-11-09
Asterisk HIGH 7.5
CVE-2017-14603

In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cer…

Mitigation only
Fix from $1,950 2017-10-10
Asterisk Gui HIGH 8.8
CVE-2017-14001EPSS 6%

An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injec…

Fix: after 2.1.0
Fix from $1,950 2017-09-26
Asterisk CRITICAL 9.8
CVE-2017-14100EPSS 15%

In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cer…

Patch available
Fix from $2,300 2017-09-02
Asterisk HIGH 7.5
CVE-2017-14098EPSS 50%

In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact…

Patch available
Fix from $1,950 2017-09-02
Asterisk HIGH 7.5
CVE-2017-14099

In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17…

Patch available
Fix from $1,950 2017-09-02
Addons Module MEDIUM 6.1
CVE-2015-2690

Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumaddoninstaller) before 2.11.0.7 …

Patch available
Fix from $1,600 2017-08-02