CVE-2019-13161
- EPSS 2.29%
- Published 12.07.2019 20:15:11
- Last modified 21.11.2024 04:24:19
An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to...
CVE-2019-12827
- EPSS 19.59%
- Published 12.07.2019 20:15:11
- Last modified 21.11.2024 04:23:40
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
CVE-2018-17281
- EPSS 80.65%
- Published 24.09.2018 22:29:01
- Last modified 21.11.2024 03:54:10
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a speci...
CVE-2018-12227
- EPSS 1.06%
- Published 12.06.2018 04:29:00
- Last modified 21.11.2024 03:44:49
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP reque...
CVE-2018-7286
- EPSS 54.63%
- Published 22.02.2018 00:29:01
- Last modified 21.11.2024 04:11:56
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of S...
CVE-2018-7284
- EPSS 65.24%
- Published 22.02.2018 00:29:01
- Last modified 21.11.2024 04:11:56
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats...
CVE-2017-17850
- EPSS 72.18%
- Published 27.12.2017 17:08:20
- Last modified 20.04.2025 01:37:25
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if t...
CVE-2017-17664
- EPSS 3.14%
- Published 13.12.2017 20:29:00
- Last modified 20.04.2025 01:37:25
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.
CVE-2017-17090
- EPSS 90.08%
- Published 02.12.2017 00:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain re...
CVE-2017-16672
- EPSS 5.27%
- Published 09.11.2017 00:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets reject...