Skip to content
Noroxi

digium records

119 published records for vendor digium.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
13
With a fix record
89.1%
Median publish → KEV
No record has entered KEV

All records

119 records
  • Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2

    HighCVSS 7.5Proof of conceptEPSS 86%

    digium · asteriskOct 23, 2006

  • An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As

    HighCVSS 7.5Proof of conceptEPSS 82%

    digium · certified asteriskDec 1, 2017

  • An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older.

    HighCVSS 7.5No exploitEPSS 75%

    digium · asteriskDec 27, 2017

  • A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk thr

    HighCVSS 7.5Proof of conceptEPSS 66%

    digium · asteriskFeb 21, 2018

  • An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4.

    HighCVSS 8.8No exploitEPSS 50%

    digium · asteriskNov 22, 2019

  • There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x

    HighCVSS 7.5No exploitEPSS 52%

    digium · asteriskSep 24, 2018

  • In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, o

    HighCVSS 7.5No exploitEPSS 50%

    digium · asteriskSep 2, 2017

  • Asterisk Path Traversal vulnerability

    HighCVSS 7.5No exploitEPSS 45%

    digium · asteriskDec 14, 2023

  • In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before

    CriticalCVSS 9.8No exploitEPSS 15%

    digium · asteriskSep 2, 2017

  • An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert

    MediumCVSS 6.5Proof of conceptEPSS 53%

    digium · asteriskFeb 21, 2018

  • An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13.

    CriticalCVSS 9.8No exploitEPSS 7%

    digium · asteriskApr 15, 2022

  • An SSRF issue was discovered in Asterisk through 19.x.

    CriticalCVSS 9.1No exploitEPSS 8%

    digium · asteriskApr 15, 2022

  • main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a cra

    HighCVSS 7.5No exploitEPSS 22%

    digium · asteriskSep 9, 2019

  • CVE-2007-1306
    37Monitor

    Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation

    HighCVSS 7.8Proof of conceptEPSS 20%

    digium · asteriskMar 6, 2007

  • An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior.

    HighCVSS 8.8No exploitEPSS 6%

    digium · asterisk guiSep 25, 2017

  • CVE-2017-7617
    37Monitor

    Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13

    HighCVSS 8.8No exploitEPSS 6%

    digium · asteriskApr 10, 2017

  • CVE-2014-8418
    37Monitor

    The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and C

    CriticalCVSS 9.0No exploitEPSS 4%

    digium · certified asteriskNov 24, 2014

  • CVE-2011-1599
    37Monitor

    manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.

    CriticalCVSS 9.0No exploitEPSS 3%

    digium · asteriskApr 26, 2011

  • A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Aster

    HighCVSS 8.8No exploitEPSS 3%

    digium · asteriskNov 8, 2017

  • An issue was discovered in Asterisk through 19.x.

    HighCVSS 7.5No exploitEPSS 17%

    digium · asteriskApr 15, 2022

  • CVE-2012-1184
    35Monitor

    Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows

    HighCVSS 7.5Proof of conceptEPSS 16%

    digium · asteriskSep 18, 2012

  • CVE-2014-2286
    35Monitor

    main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x befo

    HighCVSS 7.5No exploitEPSS 16%

    digium · asteriskApr 18, 2014

  • An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x.

    HighCVSS 7.5No exploitEPSS 13%

    digium · asteriskNov 22, 2019

  • A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified As

    MediumCVSS 5.9No exploitEPSS 32%

    digium · asteriskDec 13, 2017

  • An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certif

    HighCVSS 7.5No exploitEPSS 9%

    digium · asteriskJul 30, 2021