Digium

Asterisk

114 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.63%
  • Published 17.04.2017 16:59:00
  • Last modified 20.04.2025 01:37:25

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

  • EPSS 18.44%
  • Published 10.04.2017 14:59:00
  • Last modified 20.04.2025 01:37:25

Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan...

  • EPSS 1.92%
  • Published 12.12.2016 21:59:01
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.8-cert4. The chan_sip channel driver has a liberal definition for white...

  • EPSS 0.34%
  • Published 12.12.2016 21:59:00
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Asterisk Open Source 13.12.x and 13.13.x before 13.13.1 and 14.x before 14.2.1. If an SDP offer or answer is received with the Opus codec and with the format parameters separated using a space the code responsible for parsi...

Exploit
  • EPSS 1.09%
  • Published 22.02.2016 15:59:02
  • Last modified 12.04.2025 10:46:40

chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3, when the timert1 sip.conf configuration is set to a value greater than 1245,...

  • EPSS 7.85%
  • Published 22.02.2016 15:59:01
  • Last modified 12.04.2025 10:46:40

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to cause a denial of service (uninitialized pointer dere...

  • EPSS 39.03%
  • Published 10.04.2015 15:00:10
  • Last modified 12.04.2025 10:46:40

Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 13.1-cert2, when registering a SIP TLS device, does ...

  • EPSS 17.45%
  • Published 09.02.2015 11:59:00
  • Last modified 12.04.2025 10:46:40

Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP of...

  • EPSS 49.12%
  • Published 12.12.2014 15:59:14
  • Last modified 12.04.2025 10:46:40

Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified Asterisk 11.6 before 11.6-cert9 allows remote attackers to cause a den...

  • EPSS 1.52%
  • Published 26.11.2014 15:59:02
  • Last modified 12.04.2025 10:46:40

Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, w...