CVE-2020-28327
- EPSS 2.76%
- Veröffentlicht 06.11.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:22:33
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return ...
CVE-2020-28242
- EPSS 0.41%
- Veröffentlicht 06.11.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 05:22:30
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in...
CVE-2009-3723
- EPSS 0.65%
- Veröffentlicht 29.10.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 01:08:03
asterisk allows calls on prohibited networks
CVE-2018-12228
- EPSS 0.42%
- Veröffentlicht 12.06.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:49
An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infinite loop while trying to read t...
CVE-2017-9358
- EPSS 1.19%
- Veröffentlicht 02.06.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and...
- EPSS 0.47%
- Veröffentlicht 31.08.2012 14:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asteri...
- EPSS 3.93%
- Veröffentlicht 02.06.2012 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL poi...
CVE-2009-2346
- EPSS 0.84%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800...