Digium / Asterisk
114 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-49786 | Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation | HIGH | 7.5 | Dec 14, 2023 |
| CVE-2023-37457 | Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update' | HIGH | 8.2 | Dec 14, 2023 |
| CVE-2023-49294 | Asterisk Path Traversal vulnerability | HIGH | 7.5 | Dec 14, 2023 |
| CVE-2021-46837 | res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker… | MEDIUM | 6.5 | Aug 30, 2022 |
| CVE-2022-26651 | An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functio… | CRITICAL | 9.8 | Apr 15, 2022 |
| CVE-2022-26499 | An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as loc… | CRITICAL | 9.1 | Apr 15, 2022 |
| CVE-2022-26498 | An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much… | HIGH | 7.5 | Apr 15, 2022 |
| CVE-2021-32558 | An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before… | HIGH | 7.5 | Jul 27, 2021 |
| CVE-2021-31878 | An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a B… | MEDIUM | 6.5 | Jul 27, 2021 |
| CVE-2021-26713 | A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk befor… | MEDIUM | 6.5 | Feb 19, 2021 |
| CVE-2021-26712 | Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticat… | HIGH | 7.5 | Feb 18, 2021 |
| CVE-2020-35776 | A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by delibe… | MEDIUM | 6.5 | Feb 18, 2021 |
| CVE-2021-26906 | An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through… | MEDIUM | 5.9 | Feb 18, 2021 |
| CVE-2021-26717 | An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-n… | HIGH | 7.5 | Feb 18, 2021 |
| CVE-2020-35652 | An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1… | MEDIUM | 6.5 | Jan 29, 2021 |
| CVE-2019-18610 | An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Aste… | HIGH | 8.8 | Nov 22, 2019 |
| CVE-2019-18976 | An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38… | HIGH | 7.5 | Nov 22, 2019 |
| CVE-2019-18790 | An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.2… | MEDIUM | 6.5 | Nov 22, 2019 |
| CVE-2019-15297 | res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to… | MEDIUM | 6.5 | Sep 9, 2019 |
| CVE-2019-15639 | main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific sc… | HIGH | 7.5 | Sep 9, 2019 |
| CVE-2019-13161 | An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-ce… | MEDIUM | 5.3 | Jul 12, 2019 |
| CVE-2019-12827 | Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash… | MEDIUM | 6.5 | Jul 12, 2019 |
| CVE-2016-7550 | asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote). | HIGH | 7.5 | May 23, 2019 |
| CVE-2019-7251 | An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows re… | MEDIUM | 6.5 | Mar 28, 2019 |
| CVE-2018-19278 | Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a speci… | HIGH | 7.5 | Nov 14, 2018 |
Showing 1 to 25 of 114 CVEs