Skip to content
Noroxi

asterisk records

52 published records for vendor asterisk.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 1.9%
Pre-auth RCE
7
With a fix record
88.5%
Median publish → KEV
No record has entered KEV

All records

52 records
  • The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trig

    CriticalCVSS 10.0No exploitEPSS 4%

    asterisk · asteriskMay 7, 2007

  • Potential integer underflow upon receiving STUN message in PJSIP

    CriticalCVSS 9.8No exploitEPSS 5%

    teluu · pjsipDec 22, 2021

  • Use after free in PJSIP

    CriticalCVSS 9.8No exploitEPSS 4%

    teluu · pjsipFeb 22, 2022

  • CVE-2008-3263
    39Monitor

    The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.

    HighCVSS 7.8Proof of conceptEPSS 28%

    asterisk · asteriskJul 22, 2008

  • CVE-2007-3762
    39Monitor

    Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before

    CriticalCVSS 9.3No exploitEPSS 6%

    asterisk · asteriskJul 18, 2007

  • CVE-2008-1390
    38Monitor

    The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.

    CriticalCVSS 9.3No exploitEPSS 4%

    asterisk · asteriskMar 24, 2008

  • CVE-2007-2293
    37Monitor

    Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3

    HighCVSS 7.6Proof of conceptEPSS 24%

    asterisk · asteriskApr 26, 2007

  • Out-of-bounds read in multipart parsing in PJSIP

    CriticalCVSS 9.1No exploitEPSS 4%

    teluu · pjsipJan 26, 2022

  • CVE-2012-2186
    37Monitor

    Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris

    CriticalCVSS 9.0No exploitEPSS 4%

    asterisk · open sourceAug 31, 2012

  • Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan

    HighCVSS 8.8WeaponizedEPSS 5%

    asterisk · asteriskAug 8, 2024

  • CVE-2008-1332
    36Monitor

    Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x b

    HighCVSS 8.8No exploitEPSS 2%

    asterisk · asteriskMar 19, 2008

  • CVE-2007-1561
    35Monitor

    The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP I

    HighCVSS 7.8Proof of conceptEPSS 14%

    asterisk · asteriskMar 21, 2007

  • CVE-2008-1289
    33Monitor

    Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editi

    HighCVSS 7.5Proof of conceptEPSS 12%

    asterisk · asterisk appliance developer kitMar 24, 2008

  • CVE-2007-2294
    32Monitor

    The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using

    HighCVSS 7.8No exploitEPSS 4%

    asterisk · asteriskApr 26, 2007

  • CVE-2008-3264
    32Monitor

    The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition

    HighCVSS 7.8No exploitEPSS 3%

    asterisk · s800i applianceJul 24, 2008

  • CVE-2007-1594
    32Monitor

    The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of ser

    HighCVSS 7.8No exploitEPSS 3%

    asterisk · asteriskMar 22, 2007

  • CVE-2009-2346
    32Monitor

    The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x be

    HighCVSS 7.8No exploitEPSS 3%

    asterisk · asteriskSep 8, 2009

  • CVE-2007-2297
    32Monitor

    The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not conta

    HighCVSS 7.8No exploitEPSS 2%

    asterisk · asteriskApr 26, 2007

  • CVE-2017-9358
    31Monitor

    A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 bef

    HighCVSS 7.5No exploitEPSS 3%

    asterisk · certified asteriskJun 2, 2017

  • CVE-2007-5488
    31Monitor

    Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to

    HighCVSS 7.5Proof of conceptEPSS 3%

    asterisk · asterisk-addonsOct 17, 2007

  • CVE-2013-2685
    31Monitor

    Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbi

    HighCVSS 7.5No exploitEPSS 3%

    asterisk · open sourceApr 1, 2013

  • CVE-2007-1595
    31Monitor

    The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to e

    HighCVSS 7.5No exploitEPSS 3%

    asterisk · asteriskMar 22, 2007

  • CVE-2007-3764
    29Monitor

    The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW befor

    MediumCVSS 5.0Proof of conceptEPSS 32%

    asterisk · asteriskJul 18, 2007

  • CVE-2007-3763
    28Monitor

    The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before be

    MediumCVSS 5.0Proof of conceptEPSS 27%

    asterisk · asteriskJul 18, 2007

  • CVE-2008-0095
    28Monitor

    The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance

    MediumCVSS 5.0Proof of conceptEPSS 25%

    asterisk · asterisk appliance developer kitJan 7, 2008