Записи asterisk
52 опубликованных записей вендора asterisk.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 1,9 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 88,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-287 Improper Authentication5
- CWE-399 Resource Management Errors4
- CWE-20 Improper Input Validation3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-189 Numeric Errors2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
52 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-2488Эксплойта нет | The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigasterisk · asterisk | Критическая10,0 | — | 4,3 % | 7 мая 2007 г. |
40В плане | CVE-2021-37706Эксплойта нет | Potential integer underflow upon receiving STUN message in PJSIPteluu · pjsip · CWE-191 | Критическая9,8 | — | 4,6 % | 22 дек. 2021 г. |
40В плане | CVE-2022-23608Эксплойта нет | Use after free in PJSIPteluu · pjsip · CWE-416 | Критическая9,8 | — | 4,0 % | 22 февр. 2022 г. |
39Наблюдать | CVE-2008-3263Proof of concept | The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.asterisk · asterisk · CWE-399 | Высокая7,8 | — | 28,0 % | 22 июл. 2008 г. |
39Наблюдать | CVE-2007-3762Эксплойта нет | Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition beforeasterisk · asterisk | Критическая9,3 | — | 5,5 % | 18 июл. 2007 г. |
38Наблюдать | CVE-2008-1390Эксплойта нет | The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.asterisk · asterisk · CWE-255 | Критическая9,3 | — | 3,8 % | 24 мар. 2008 г. |
37Наблюдать | CVE-2007-2293Proof of concept | Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 asterisk · asterisk | Высокая7,6 | — | 23,9 % | 26 апр. 2007 г. |
37Наблюдать | CVE-2022-21723Эксплойта нет | Out-of-bounds read in multipart parsing in PJSIPteluu · pjsip · CWE-125 | Критическая9,1 | — | 4,4 % | 26 янв. 2022 г. |
37Наблюдать | CVE-2012-2186Эксплойта нет | Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisasterisk · open source | Критическая9,0 | — | 3,6 % | 31 авг. 2012 г. |
36Наблюдать | CVE-2024-42365Готовый эксплойт | Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplanasterisk · asterisk · CWE-267 | Высокая8,8 | — | 4,7 % | 8 авг. 2024 г. |
36Наблюдать | CVE-2008-1332Эксплойта нет | Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x basterisk · asterisk · CWE-264 | Высокая8,8 | — | 2,3 % | 19 мар. 2008 г. |
35Наблюдать | CVE-2007-1561Proof of concept | The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Iasterisk · asterisk | Высокая7,8 | — | 14,5 % | 21 мар. 2007 г. |
33Наблюдать | CVE-2008-1289Proof of concept | Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editiasterisk · asterisk appliance developer kit · CWE-119 | Высокая7,5 | — | 11,5 % | 24 мар. 2008 г. |
32Наблюдать | CVE-2007-2294Эксплойта нет | The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by usingasterisk · asterisk | Высокая7,8 | — | 3,9 % | 26 апр. 2007 г. |
32Наблюдать | CVE-2008-3264Эксплойта нет | The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Editionasterisk · s800i appliance · CWE-287 | Высокая7,8 | — | 3,4 % | 24 июл. 2008 г. |
32Наблюдать | CVE-2007-1594Эксплойта нет | The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of serasterisk · asterisk | Высокая7,8 | — | 2,6 % | 22 мар. 2007 г. |
32Наблюдать | CVE-2009-2346Эксплойта нет | The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x beasterisk · asterisk · CWE-119 | Высокая7,8 | — | 2,6 % | 8 сент. 2009 г. |
32Наблюдать | CVE-2007-2297Эксплойта нет | The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contaasterisk · asterisk | Высокая7,8 | — | 2,4 % | 26 апр. 2007 г. |
31Наблюдать | CVE-2017-9358Эксплойта нет | A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 befasterisk · certified asterisk · CWE-835 | Высокая7,5 | — | 2,7 % | 2 июн. 2017 г. |
31Наблюдать | CVE-2007-5488Proof of concept | Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers toasterisk · asterisk-addons · CWE-89 | Высокая7,5 | — | 2,7 % | 17 окт. 2007 г. |
31Наблюдать | CVE-2013-2685Эксплойта нет | Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbiasterisk · open source · CWE-119 | Высокая7,5 | — | 2,6 % | 1 апр. 2013 г. |
31Наблюдать | CVE-2007-1595Эксплойта нет | The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to easterisk · asterisk | Высокая7,5 | — | 2,6 % | 22 мар. 2007 г. |
29Наблюдать | CVE-2007-3764Proof of concept | The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW beforasterisk · asterisk | Средняя5,0 | — | 31,5 % | 18 июл. 2007 г. |
28Наблюдать | CVE-2007-3763Proof of concept | The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beasterisk · asterisk | Средняя5,0 | — | 26,6 % | 18 июл. 2007 г. |
28Наблюдать | CVE-2008-0095Proof of concept | The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Applianceasterisk · asterisk appliance developer kit · CWE-399 | Средняя5,0 | — | 25,4 % | 7 янв. 2008 г. |
- CVE-2007-248841В плане
The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trig
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %asterisk · asterisk7 мая 2007 г.
- CVE-2021-3770640В плане
Potential integer underflow upon receiving STUN message in PJSIP
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %teluu · pjsip22 дек. 2021 г.
- CVE-2022-2360840В плане
Use after free in PJSIP
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %teluu · pjsip22 февр. 2022 г.
- CVE-2008-326339Наблюдать
The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.
ВысокаяCVSS 7,8Proof of conceptEPSS 28 %asterisk · asterisk22 июл. 2008 г.
- CVE-2007-376239Наблюдать
Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %asterisk · asterisk18 июл. 2007 г.
- CVE-2008-139038Наблюдать
The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %asterisk · asterisk24 мар. 2008 г.
- CVE-2007-229337Наблюдать
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3
ВысокаяCVSS 7,6Proof of conceptEPSS 24 %asterisk · asterisk26 апр. 2007 г.
- CVE-2022-2172337Наблюдать
Out-of-bounds read in multipart parsing in PJSIP
КритическаяCVSS 9,1Эксплойта нетEPSS 4 %teluu · pjsip26 янв. 2022 г.
- CVE-2012-218637Наблюдать
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris
КритическаяCVSS 9,0Эксплойта нетEPSS 4 %asterisk · open source31 авг. 2012 г.
- CVE-2024-4236536Наблюдать
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
ВысокаяCVSS 8,8Готовый эксплойтEPSS 5 %asterisk · asterisk8 авг. 2024 г.
- CVE-2008-133236Наблюдать
Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x b
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %asterisk · asterisk19 мар. 2008 г.
- CVE-2007-156135Наблюдать
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP I
ВысокаяCVSS 7,8Proof of conceptEPSS 14 %asterisk · asterisk21 мар. 2007 г.
- CVE-2008-128933Наблюдать
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editi
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %asterisk · asterisk appliance developer kit24 мар. 2008 г.
- CVE-2007-229432Наблюдать
The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %asterisk · asterisk26 апр. 2007 г.
- CVE-2008-326432Наблюдать
The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %asterisk · s800i appliance24 июл. 2008 г.
- CVE-2007-159432Наблюдать
The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of ser
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %asterisk · asterisk22 мар. 2007 г.
- CVE-2009-234632Наблюдать
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x be
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %asterisk · asterisk8 сент. 2009 г.
- CVE-2007-229732Наблюдать
The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not conta
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %asterisk · asterisk26 апр. 2007 г.
- CVE-2017-935831Наблюдать
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 bef
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %asterisk · certified asterisk2 июн. 2017 г.
- CVE-2007-548831Наблюдать
Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %asterisk · asterisk-addons17 окт. 2007 г.
- CVE-2013-268531Наблюдать
Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbi
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %asterisk · open source1 апр. 2013 г.
- CVE-2007-159531Наблюдать
The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to e
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %asterisk · asterisk22 мар. 2007 г.
- CVE-2007-376429Наблюдать
The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW befor
СредняяCVSS 5,0Proof of conceptEPSS 32 %asterisk · asterisk18 июл. 2007 г.
- CVE-2007-376328Наблюдать
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before be
СредняяCVSS 5,0Proof of conceptEPSS 27 %asterisk · asterisk18 июл. 2007 г.
- CVE-2008-009528Наблюдать
The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance
СредняяCVSS 5,0Proof of conceptEPSS 25 %asterisk · asterisk appliance developer kit7 янв. 2008 г.