asterisk records
52 published records for vendor asterisk.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 1.9%
- Pre-auth RCE
- 7
- With a fix record
- 88.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-287 Improper Authentication5
- CWE-399 Resource Management Errors4
- CWE-20 Improper Input Validation3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-189 Numeric Errors2
The weakness classes this vendor ships most often: where to look.
CWEAll records
52 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2007-2488No exploit | The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigasterisk · asterisk | Critical10.0 | — | 4.3% | May 7, 2007 |
40Plan | CVE-2021-37706No exploit | Potential integer underflow upon receiving STUN message in PJSIPteluu · pjsip · CWE-191 | Critical9.8 | — | 4.6% | Dec 22, 2021 |
40Plan | CVE-2022-23608No exploit | Use after free in PJSIPteluu · pjsip · CWE-416 | Critical9.8 | — | 4.0% | Feb 22, 2022 |
39Monitor | CVE-2008-3263Proof of concept | The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.asterisk · asterisk · CWE-399 | High7.8 | — | 28.0% | Jul 22, 2008 |
39Monitor | CVE-2007-3762No exploit | Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition beforeasterisk · asterisk | Critical9.3 | — | 5.5% | Jul 18, 2007 |
38Monitor | CVE-2008-1390No exploit | The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.asterisk · asterisk · CWE-255 | Critical9.3 | — | 3.8% | Mar 24, 2008 |
37Monitor | CVE-2007-2293Proof of concept | Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 asterisk · asterisk | High7.6 | — | 23.9% | Apr 26, 2007 |
37Monitor | CVE-2022-21723No exploit | Out-of-bounds read in multipart parsing in PJSIPteluu · pjsip · CWE-125 | Critical9.1 | — | 4.4% | Jan 26, 2022 |
37Monitor | CVE-2012-2186No exploit | Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisasterisk · open source | Critical9.0 | — | 3.6% | Aug 31, 2012 |
36Monitor | CVE-2024-42365Weaponized | Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplanasterisk · asterisk · CWE-267 | High8.8 | — | 4.7% | Aug 8, 2024 |
36Monitor | CVE-2008-1332No exploit | Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x basterisk · asterisk · CWE-264 | High8.8 | — | 2.3% | Mar 19, 2008 |
35Monitor | CVE-2007-1561Proof of concept | The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Iasterisk · asterisk | High7.8 | — | 14.5% | Mar 21, 2007 |
33Monitor | CVE-2008-1289Proof of concept | Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editiasterisk · asterisk appliance developer kit · CWE-119 | High7.5 | — | 11.5% | Mar 24, 2008 |
32Monitor | CVE-2007-2294No exploit | The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by usingasterisk · asterisk | High7.8 | — | 3.9% | Apr 26, 2007 |
32Monitor | CVE-2008-3264No exploit | The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Editionasterisk · s800i appliance · CWE-287 | High7.8 | — | 3.4% | Jul 24, 2008 |
32Monitor | CVE-2007-1594No exploit | The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of serasterisk · asterisk | High7.8 | — | 2.6% | Mar 22, 2007 |
32Monitor | CVE-2009-2346No exploit | The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x beasterisk · asterisk · CWE-119 | High7.8 | — | 2.6% | Sep 8, 2009 |
32Monitor | CVE-2007-2297No exploit | The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contaasterisk · asterisk | High7.8 | — | 2.4% | Apr 26, 2007 |
31Monitor | CVE-2017-9358No exploit | A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 befasterisk · certified asterisk · CWE-835 | High7.5 | — | 2.7% | Jun 2, 2017 |
31Monitor | CVE-2007-5488Proof of concept | Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers toasterisk · asterisk-addons · CWE-89 | High7.5 | — | 2.7% | Oct 17, 2007 |
31Monitor | CVE-2013-2685No exploit | Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbiasterisk · open source · CWE-119 | High7.5 | — | 2.6% | Apr 1, 2013 |
31Monitor | CVE-2007-1595No exploit | The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to easterisk · asterisk | High7.5 | — | 2.6% | Mar 22, 2007 |
29Monitor | CVE-2007-3764Proof of concept | The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW beforasterisk · asterisk | Medium5.0 | — | 31.5% | Jul 18, 2007 |
28Monitor | CVE-2007-3763Proof of concept | The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beasterisk · asterisk | Medium5.0 | — | 26.6% | Jul 18, 2007 |
28Monitor | CVE-2008-0095Proof of concept | The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Applianceasterisk · asterisk appliance developer kit · CWE-399 | Medium5.0 | — | 25.4% | Jan 7, 2008 |
- CVE-2007-248841Plan
The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trig
CriticalCVSS 10.0No exploitEPSS 4%asterisk · asteriskMay 7, 2007
- CVE-2021-3770640Plan
Potential integer underflow upon receiving STUN message in PJSIP
CriticalCVSS 9.8No exploitEPSS 5%teluu · pjsipDec 22, 2021
- CVE-2022-2360840Plan
Use after free in PJSIP
CriticalCVSS 9.8No exploitEPSS 4%teluu · pjsipFeb 22, 2022
- CVE-2008-326339Monitor
The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.
HighCVSS 7.8Proof of conceptEPSS 28%asterisk · asteriskJul 22, 2008
- CVE-2007-376239Monitor
Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before
CriticalCVSS 9.3No exploitEPSS 6%asterisk · asteriskJul 18, 2007
- CVE-2008-139038Monitor
The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.
CriticalCVSS 9.3No exploitEPSS 4%asterisk · asteriskMar 24, 2008
- CVE-2007-229337Monitor
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3
HighCVSS 7.6Proof of conceptEPSS 24%asterisk · asteriskApr 26, 2007
- CVE-2022-2172337Monitor
Out-of-bounds read in multipart parsing in PJSIP
CriticalCVSS 9.1No exploitEPSS 4%teluu · pjsipJan 26, 2022
- CVE-2012-218637Monitor
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris
CriticalCVSS 9.0No exploitEPSS 4%asterisk · open sourceAug 31, 2012
- CVE-2024-4236536Monitor
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
HighCVSS 8.8WeaponizedEPSS 5%asterisk · asteriskAug 8, 2024
- CVE-2008-133236Monitor
Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x b
HighCVSS 8.8No exploitEPSS 2%asterisk · asteriskMar 19, 2008
- CVE-2007-156135Monitor
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP I
HighCVSS 7.8Proof of conceptEPSS 14%asterisk · asteriskMar 21, 2007
- CVE-2008-128933Monitor
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editi
HighCVSS 7.5Proof of conceptEPSS 12%asterisk · asterisk appliance developer kitMar 24, 2008
- CVE-2007-229432Monitor
The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using
HighCVSS 7.8No exploitEPSS 4%asterisk · asteriskApr 26, 2007
- CVE-2008-326432Monitor
The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition
HighCVSS 7.8No exploitEPSS 3%asterisk · s800i applianceJul 24, 2008
- CVE-2007-159432Monitor
The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of ser
HighCVSS 7.8No exploitEPSS 3%asterisk · asteriskMar 22, 2007
- CVE-2009-234632Monitor
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x be
HighCVSS 7.8No exploitEPSS 3%asterisk · asteriskSep 8, 2009
- CVE-2007-229732Monitor
The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not conta
HighCVSS 7.8No exploitEPSS 2%asterisk · asteriskApr 26, 2007
- CVE-2017-935831Monitor
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 bef
HighCVSS 7.5No exploitEPSS 3%asterisk · certified asteriskJun 2, 2017
- CVE-2007-548831Monitor
Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to
HighCVSS 7.5Proof of conceptEPSS 3%asterisk · asterisk-addonsOct 17, 2007
- CVE-2013-268531Monitor
Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbi
HighCVSS 7.5No exploitEPSS 3%asterisk · open sourceApr 1, 2013
- CVE-2007-159531Monitor
The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to e
HighCVSS 7.5No exploitEPSS 3%asterisk · asteriskMar 22, 2007
- CVE-2007-376429Monitor
The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW befor
MediumCVSS 5.0Proof of conceptEPSS 32%asterisk · asteriskJul 18, 2007
- CVE-2007-376328Monitor
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before be
MediumCVSS 5.0Proof of conceptEPSS 27%asterisk · asteriskJul 18, 2007
- CVE-2008-009528Monitor
The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance
MediumCVSS 5.0Proof of conceptEPSS 25%asterisk · asterisk appliance developer kitJan 7, 2008