- EPSS 2.45%
- Veröffentlicht 01.04.2013 16:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
main/http.c in the HTTP server in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1.8.15-cert2; and Asterisk Digiumphones 10.x-digiumphones before 10.12.2-digiumphones does not...
CVE-2013-2685
- EPSS 8.93%
- Veröffentlicht 01.04.2013 16:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary code via a long sprop-parameter-sets H.264 media attribute in a SIP Session Description Protocol (SDP) h...
- EPSS 0.17%
- Veröffentlicht 01.04.2013 16:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SIP channel driver in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1.8.15-cert2; Asterisk Business Edition (BE) C.3.x before C.3.8.1; and Asterisk Digiumphones 10.x-digi...
- EPSS 0.47%
- Veröffentlicht 31.08.2012 14:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asteri...
- EPSS 3.93%
- Veröffentlicht 02.06.2012 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL poi...
CVE-2012-2416
- EPSS 5.05%
- Veröffentlicht 30.04.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4, when the trustrpid option is enabled, allows remote authenticated users to cause a denial of...
CVE-2012-2415
- EPSS 10.53%
- Veröffentlicht 30.04.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remote authenticated users to cause a denial of service or possibly have un...
CVE-2012-2414
- EPSS 4.28%
- Veröffentlicht 30.04.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirement...
CVE-2012-0885
- EPSS 1.06%
- Veröffentlicht 25.01.2012 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
chan_sip.c in Asterisk Open Source 1.8.x before 1.8.8.2 and 10.x before 10.0.1, when the res_srtp module is used and media support is improperly configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cra...
CVE-2011-4063
- EPSS 6.7%
- Veröffentlicht 21.10.2011 10:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which allows remote authenticated users to cause a denial of service (daemon c...