digium records
119 published records for vendor digium.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 13
- With a fix record
- 89.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer17
- CWE-20 Improper Input Validation14
- CWE-399 Resource Management Errors8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-476 NULL Pointer Dereference6
- CWE-264 Permissions, Privileges, and Access Controls6
The weakness classes this vendor ships most often: where to look.
CWEAll records
119 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2006-5444Proof of concept | Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2digium · asterisk | High7.5 | — | 86.5% | Oct 23, 2006 |
55Plan | CVE-2017-17090Proof of concept | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asdigium · certified asterisk · CWE-459 | High7.5 | — | 82.2% | Dec 1, 2017 |
53Plan | CVE-2017-17850No exploit | An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older.digium · asterisk · CWE-20 | High7.5 | — | 75.4% | Dec 27, 2017 |
50Plan | CVE-2018-7284Proof of concept | A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk thrdigium · asterisk · CWE-119 | High7.5 | — | 66.2% | Feb 21, 2018 |
50Plan | CVE-2019-18610No exploit | An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4.digium · asterisk · CWE-862 | High8.8 | — | 50.1% | Nov 22, 2019 |
46Plan | CVE-2018-17281No exploit | There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x digium · asterisk · CWE-400 | High7.5 | — | 52.4% | Sep 24, 2018 |
45Plan | CVE-2017-14098No exploit | In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, odigium · asterisk · CWE-20 | High7.5 | — | 50.1% | Sep 2, 2017 |
44Plan | CVE-2023-49294No exploit | Asterisk Path Traversal vulnerabilitydigium · asterisk · CWE-22 | High7.5 | — | 45.3% | Dec 14, 2023 |
43Plan | CVE-2017-14100No exploit | In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before digium · asterisk · CWE-78 | Critical9.8 | — | 14.9% | Sep 2, 2017 |
42Plan | CVE-2018-7286Proof of concept | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-certdigium · asterisk | Medium6.5 | — | 52.7% | Feb 21, 2018 |
41Plan | CVE-2022-26651No exploit | An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13.digium · asterisk · CWE-89 | Critical9.8 | — | 7.0% | Apr 15, 2022 |
38Monitor | CVE-2022-26499No exploit | An SSRF issue was discovered in Asterisk through 19.x.digium · asterisk · CWE-918 | Critical9.1 | — | 7.8% | Apr 15, 2022 |
37Monitor | CVE-2019-15639No exploit | main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a cradigium · asterisk · CWE-20 | High7.5 | — | 21.9% | Sep 9, 2019 |
37Monitor | CVE-2007-1306Proof of concept | Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiationdigium · asterisk | High7.8 | — | 20.3% | Mar 6, 2007 |
37Monitor | CVE-2017-14001No exploit | An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior.digium · asterisk gui · CWE-78 | High8.8 | — | 6.4% | Sep 25, 2017 |
37Monitor | CVE-2017-7617No exploit | Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13digium · asterisk · CWE-119 | High8.8 | — | 6.2% | Apr 10, 2017 |
37Monitor | CVE-2014-8418No exploit | The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Cdigium · certified asterisk · CWE-264 | Critical9.0 | — | 3.6% | Nov 24, 2014 |
37Monitor | CVE-2011-1599No exploit | manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.digium · asterisk · CWE-20 | Critical9.0 | — | 3.1% | Apr 26, 2011 |
36Monitor | CVE-2017-16671No exploit | A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterdigium · asterisk · CWE-119 | High8.8 | — | 3.3% | Nov 8, 2017 |
35Monitor | CVE-2022-26498No exploit | An issue was discovered in Asterisk through 19.x.digium · asterisk · CWE-400 | High7.5 | — | 16.7% | Apr 15, 2022 |
35Monitor | CVE-2012-1184Proof of concept | Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allowsdigium · asterisk · CWE-119 | High7.5 | — | 16.4% | Sep 18, 2012 |
35Monitor | CVE-2014-2286No exploit | main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x befodigium · asterisk · CWE-20 | High7.5 | — | 16.4% | Apr 18, 2014 |
34Monitor | CVE-2019-18976No exploit | An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x.digium · asterisk · CWE-476 | High7.5 | — | 12.8% | Nov 22, 2019 |
33Monitor | CVE-2017-17664No exploit | A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asdigium · asterisk · CWE-119 | Medium5.9 | — | 32.4% | Dec 13, 2017 |
33Monitor | CVE-2021-32558No exploit | An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certifdigium · asterisk · CWE-74 | High7.5 | — | 9.2% | Jul 30, 2021 |
- CVE-2006-544456Plan
Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2
HighCVSS 7.5Proof of conceptEPSS 86%digium · asteriskOct 23, 2006
- CVE-2017-1709055Plan
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As
HighCVSS 7.5Proof of conceptEPSS 82%digium · certified asteriskDec 1, 2017
- CVE-2017-1785053Plan
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older.
HighCVSS 7.5No exploitEPSS 75%digium · asteriskDec 27, 2017
- CVE-2018-728450Plan
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk thr
HighCVSS 7.5Proof of conceptEPSS 66%digium · asteriskFeb 21, 2018
- CVE-2019-1861050Plan
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4.
HighCVSS 8.8No exploitEPSS 50%digium · asteriskNov 22, 2019
- CVE-2018-1728146Plan
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x
HighCVSS 7.5No exploitEPSS 52%digium · asteriskSep 24, 2018
- CVE-2017-1409845Plan
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, o
HighCVSS 7.5No exploitEPSS 50%digium · asteriskSep 2, 2017
- CVE-2023-4929444Plan
Asterisk Path Traversal vulnerability
HighCVSS 7.5No exploitEPSS 45%digium · asteriskDec 14, 2023
- CVE-2017-1410043Plan
In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before
CriticalCVSS 9.8No exploitEPSS 15%digium · asteriskSep 2, 2017
- CVE-2018-728642Plan
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert
MediumCVSS 6.5Proof of conceptEPSS 53%digium · asteriskFeb 21, 2018
- CVE-2022-2665141Plan
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13.
CriticalCVSS 9.8No exploitEPSS 7%digium · asteriskApr 15, 2022
- CVE-2022-2649938Monitor
An SSRF issue was discovered in Asterisk through 19.x.
CriticalCVSS 9.1No exploitEPSS 8%digium · asteriskApr 15, 2022
- CVE-2019-1563937Monitor
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a cra
HighCVSS 7.5No exploitEPSS 22%digium · asteriskSep 9, 2019
- CVE-2007-130637Monitor
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation
HighCVSS 7.8Proof of conceptEPSS 20%digium · asteriskMar 6, 2007
- CVE-2017-1400137Monitor
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior.
HighCVSS 8.8No exploitEPSS 6%digium · asterisk guiSep 25, 2017
- CVE-2017-761737Monitor
Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13
HighCVSS 8.8No exploitEPSS 6%digium · asteriskApr 10, 2017
- CVE-2014-841837Monitor
The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and C
CriticalCVSS 9.0No exploitEPSS 4%digium · certified asteriskNov 24, 2014
- CVE-2011-159937Monitor
manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.
CriticalCVSS 9.0No exploitEPSS 3%digium · asteriskApr 26, 2011
- CVE-2017-1667136Monitor
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Aster
HighCVSS 8.8No exploitEPSS 3%digium · asteriskNov 8, 2017
- CVE-2022-2649835Monitor
An issue was discovered in Asterisk through 19.x.
HighCVSS 7.5No exploitEPSS 17%digium · asteriskApr 15, 2022
- CVE-2012-118435Monitor
Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows
HighCVSS 7.5Proof of conceptEPSS 16%digium · asteriskSep 18, 2012
- CVE-2014-228635Monitor
main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x befo
HighCVSS 7.5No exploitEPSS 16%digium · asteriskApr 18, 2014
- CVE-2019-1897634Monitor
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x.
HighCVSS 7.5No exploitEPSS 13%digium · asteriskNov 22, 2019
- CVE-2017-1766433Monitor
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified As
MediumCVSS 5.9No exploitEPSS 32%digium · asteriskDec 13, 2017
- CVE-2021-3255833Monitor
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certif
HighCVSS 7.5No exploitEPSS 9%digium · asteriskJul 30, 2021