CVE-2007-6171
- EPSS 0.24%
- Veröffentlicht 30.11.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
CVE-2007-5358
- EPSS 2.58%
- Veröffentlicht 12.10.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (...
CVE-2007-4103
- EPSS 3.12%
- Veröffentlicht 31.07.2007 10:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and Asterisk Appliance Developer Kit before 0.6.0, when configured to allow unauthenticated calls, allows remote attackers to cause a denial of service (res...
CVE-2007-1306
- EPSS 18.7%
- Veröffentlicht 07.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.
CVE-2006-5444
- EPSS 87.06%
- Veröffentlicht 23.10.2006 17:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allows remote attackers to execute arbitrary code via a certain dlen value ...
CVE-2006-5445
- EPSS 7.93%
- Veröffentlicht 23.10.2006 17:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the SIP channel driver (channels/chan_sip.c) in Asterisk 1.2.x before 1.2.13 and 1.4.x before 1.4.0-beta3 allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors that result in ...
CVE-2006-4345
- EPSS 5.15%
- Veröffentlicht 24.08.2006 20:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in channels/chan_mgcp.c in MGCP in Asterisk 1.0 through 1.2.10 allows remote attackers to execute arbitrary code via a crafted audit endpoint (AUEP) response.
CVE-2006-4346
- EPSS 2.33%
- Veröffentlicht 24.08.2006 20:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Asterisk 1.2.10 supports the use of client-controlled variables to determine filenames in the Record function, which allows remote attackers to (1) execute code via format string specifiers or (2) overwrite files via directory traversals involving un...
CVE-2006-2898
- EPSS 0.32%
- Veröffentlicht 07.06.2006 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and 1.0.x before 1.0.11 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2 (IAX2) video frames, which bypasses a length check...
CVE-2006-1827
- EPSS 3.38%
- Veröffentlicht 18.04.2006 20:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigne...