CVE-2024-53566
- EPSS 0.02%
- Veröffentlicht 02.12.2024 18:15:11
- Zuletzt bearbeitet 06.02.2025 02:15:10
An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.
CVE-2024-42491
- EPSS 0.44%
- Veröffentlicht 05.09.2024 18:15:05
- Zuletzt bearbeitet 26.08.2025 17:47:36
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion ...
CVE-2024-35190
- EPSS 0.24%
- Veröffentlicht 17.05.2024 17:15:07
- Zuletzt bearbeitet 26.08.2025 16:19:01
Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.
CVE-2022-42706
- EPSS 0.2%
- Veröffentlicht 05.12.2022 21:15:10
- Zuletzt bearbeitet 24.04.2025 15:15:50
An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk c...
CVE-2022-42705
- EPSS 1.03%
- Veröffentlicht 05.12.2022 21:15:10
- Zuletzt bearbeitet 24.04.2025 15:15:50
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport ...
CVE-2022-37325
- EPSS 0.27%
- Veröffentlicht 05.12.2022 21:15:10
- Zuletzt bearbeitet 24.04.2025 15:15:47
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
CVE-2022-23608
- EPSS 0.58%
- Veröffentlicht 22.02.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:55
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario...
CVE-2022-21723
- EPSS 0.27%
- Veröffentlicht 27.01.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:45:18
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a mal...
CVE-2021-37706
- EPSS 0.1%
- Veröffentlicht 22.12.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:45
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribut...
CVE-2020-28327
- EPSS 2.76%
- Veröffentlicht 06.11.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:22:33
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return ...