CVE-2009-2346
- EPSS 0.84%
- Published 08.09.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800...
- EPSS 0.69%
- Published 14.01.2009 23:30:00
- Last modified 09.04.2025 00:30:58
IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differ...
CVE-2008-5558
- EPSS 2.1%
- Published 17.12.2008 17:30:00
- Last modified 09.04.2025 00:30:58
Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts involving (1) an unknown user or...
CVE-2008-3264
- EPSS 11.36%
- Published 24.07.2008 15:41:00
- Last modified 09.04.2025 00:30:58
The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i...
CVE-2008-2119
- EPSS 13.1%
- Published 04.06.2008 19:32:00
- Last modified 09.04.2025 00:30:58
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE m...
CVE-2008-1923
- EPSS 1.53%
- Published 23.04.2008 16:05:00
- Last modified 09.04.2025 00:30:58
The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote atta...
CVE-2008-1897
- EPSS 3.48%
- Published 23.04.2008 16:05:00
- Last modified 09.04.2025 00:30:58
The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s8...
CVE-2008-1289
- EPSS 28.37%
- Published 24.03.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, a...
CVE-2008-1333
- EPSS 2.58%
- Published 20.03.2008 00:44:00
- Last modified 09.04.2025 00:30:58
Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append f...
CVE-2008-1332
- EPSS 1.06%
- Published 20.03.2008 00:44:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Appliance Developer Kit before 1.4 re...