CVE-2024-42491
- EPSS 0.44%
- Published 05.09.2024 18:15:05
- Last modified 26.08.2025 17:47:36
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion ...
CVE-2023-37457
- EPSS 0.05%
- Published 14.12.2023 20:15:52
- Last modified 21.11.2024 08:11:44
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialpla...
CVE-2023-49294
- EPSS 10.36%
- Published 14.12.2023 20:15:52
- Last modified 21.11.2024 08:33:12
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dang...
CVE-2023-49786
- EPSS 0.05%
- Published 14.12.2023 20:15:52
- Last modified 21.11.2024 08:33:50
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race condition in the he...
CVE-2022-42705
- EPSS 1.03%
- Published 05.12.2022 21:15:10
- Last modified 24.04.2025 15:15:50
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport ...
CVE-2022-42706
- EPSS 0.2%
- Published 05.12.2022 21:15:10
- Last modified 24.04.2025 15:15:50
An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk c...