Записи digium
119 опубликованных записей вендора digium.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 89,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer17
- CWE-20 Improper Input Validation14
- CWE-399 Resource Management Errors8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-476 NULL Pointer Dereference6
- CWE-264 Permissions, Privileges, and Access Controls6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
119 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
56В плане | CVE-2006-5444Proof of concept | Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2digium · asterisk | Высокая7,5 | — | 86,5 % | 23 окт. 2006 г. |
55В плане | CVE-2017-17090Proof of concept | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asdigium · certified asterisk · CWE-459 | Высокая7,5 | — | 82,2 % | 1 дек. 2017 г. |
53В плане | CVE-2017-17850Эксплойта нет | An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older.digium · asterisk · CWE-20 | Высокая7,5 | — | 75,4 % | 27 дек. 2017 г. |
50В плане | CVE-2018-7284Proof of concept | A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk thrdigium · asterisk · CWE-119 | Высокая7,5 | — | 66,2 % | 21 февр. 2018 г. |
50В плане | CVE-2019-18610Эксплойта нет | An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4.digium · asterisk · CWE-862 | Высокая8,8 | — | 50,1 % | 22 нояб. 2019 г. |
46В плане | CVE-2018-17281Эксплойта нет | There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x digium · asterisk · CWE-400 | Высокая7,5 | — | 52,4 % | 24 сент. 2018 г. |
45В плане | CVE-2017-14098Эксплойта нет | In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, odigium · asterisk · CWE-20 | Высокая7,5 | — | 50,1 % | 2 сент. 2017 г. |
44В плане | CVE-2023-49294Эксплойта нет | Asterisk Path Traversal vulnerabilitydigium · asterisk · CWE-22 | Высокая7,5 | — | 45,3 % | 14 дек. 2023 г. |
43В плане | CVE-2017-14100Эксплойта нет | In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before digium · asterisk · CWE-78 | Критическая9,8 | — | 14,9 % | 2 сент. 2017 г. |
42В плане | CVE-2018-7286Proof of concept | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-certdigium · asterisk | Средняя6,5 | — | 52,7 % | 21 февр. 2018 г. |
41В плане | CVE-2022-26651Эксплойта нет | An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13.digium · asterisk · CWE-89 | Критическая9,8 | — | 7,0 % | 15 апр. 2022 г. |
38Наблюдать | CVE-2022-26499Эксплойта нет | An SSRF issue was discovered in Asterisk through 19.x.digium · asterisk · CWE-918 | Критическая9,1 | — | 7,8 % | 15 апр. 2022 г. |
37Наблюдать | CVE-2019-15639Эксплойта нет | main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a cradigium · asterisk · CWE-20 | Высокая7,5 | — | 21,9 % | 9 сент. 2019 г. |
37Наблюдать | CVE-2007-1306Proof of concept | Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiationdigium · asterisk | Высокая7,8 | — | 20,3 % | 6 мар. 2007 г. |
37Наблюдать | CVE-2017-14001Эксплойта нет | An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior.digium · asterisk gui · CWE-78 | Высокая8,8 | — | 6,4 % | 25 сент. 2017 г. |
37Наблюдать | CVE-2017-7617Эксплойта нет | Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13digium · asterisk · CWE-119 | Высокая8,8 | — | 6,2 % | 10 апр. 2017 г. |
37Наблюдать | CVE-2014-8418Эксплойта нет | The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Cdigium · certified asterisk · CWE-264 | Критическая9,0 | — | 3,6 % | 24 нояб. 2014 г. |
37Наблюдать | CVE-2011-1599Эксплойта нет | manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.digium · asterisk · CWE-20 | Критическая9,0 | — | 3,1 % | 26 апр. 2011 г. |
36Наблюдать | CVE-2017-16671Эксплойта нет | A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterdigium · asterisk · CWE-119 | Высокая8,8 | — | 3,3 % | 8 нояб. 2017 г. |
35Наблюдать | CVE-2022-26498Эксплойта нет | An issue was discovered in Asterisk through 19.x.digium · asterisk · CWE-400 | Высокая7,5 | — | 16,7 % | 15 апр. 2022 г. |
35Наблюдать | CVE-2012-1184Proof of concept | Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allowsdigium · asterisk · CWE-119 | Высокая7,5 | — | 16,4 % | 18 сент. 2012 г. |
35Наблюдать | CVE-2014-2286Эксплойта нет | main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x befodigium · asterisk · CWE-20 | Высокая7,5 | — | 16,4 % | 18 апр. 2014 г. |
34Наблюдать | CVE-2019-18976Эксплойта нет | An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x.digium · asterisk · CWE-476 | Высокая7,5 | — | 12,8 % | 22 нояб. 2019 г. |
33Наблюдать | CVE-2017-17664Эксплойта нет | A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asdigium · asterisk · CWE-119 | Средняя5,9 | — | 32,4 % | 13 дек. 2017 г. |
33Наблюдать | CVE-2021-32558Эксплойта нет | An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certifdigium · asterisk · CWE-74 | Высокая7,5 | — | 9,2 % | 30 июл. 2021 г. |
- CVE-2006-544456В плане
Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2
ВысокаяCVSS 7,5Proof of conceptEPSS 86 %digium · asterisk23 окт. 2006 г.
- CVE-2017-1709055В плане
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As
ВысокаяCVSS 7,5Proof of conceptEPSS 82 %digium · certified asterisk1 дек. 2017 г.
- CVE-2017-1785053В плане
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older.
ВысокаяCVSS 7,5Эксплойта нетEPSS 75 %digium · asterisk27 дек. 2017 г.
- CVE-2018-728450В плане
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk thr
ВысокаяCVSS 7,5Proof of conceptEPSS 66 %digium · asterisk21 февр. 2018 г.
- CVE-2019-1861050В плане
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4.
ВысокаяCVSS 8,8Эксплойта нетEPSS 50 %digium · asterisk22 нояб. 2019 г.
- CVE-2018-1728146В плане
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x
ВысокаяCVSS 7,5Эксплойта нетEPSS 52 %digium · asterisk24 сент. 2018 г.
- CVE-2017-1409845В плане
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, o
ВысокаяCVSS 7,5Эксплойта нетEPSS 50 %digium · asterisk2 сент. 2017 г.
- CVE-2023-4929444В плане
Asterisk Path Traversal vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 45 %digium · asterisk14 дек. 2023 г.
- CVE-2017-1410043В плане
In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %digium · asterisk2 сент. 2017 г.
- CVE-2018-728642В плане
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert
СредняяCVSS 6,5Proof of conceptEPSS 53 %digium · asterisk21 февр. 2018 г.
- CVE-2022-2665141В плане
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %digium · asterisk15 апр. 2022 г.
- CVE-2022-2649938Наблюдать
An SSRF issue was discovered in Asterisk through 19.x.
КритическаяCVSS 9,1Эксплойта нетEPSS 8 %digium · asterisk15 апр. 2022 г.
- CVE-2019-1563937Наблюдать
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a cra
ВысокаяCVSS 7,5Эксплойта нетEPSS 22 %digium · asterisk9 сент. 2019 г.
- CVE-2007-130637Наблюдать
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation
ВысокаяCVSS 7,8Proof of conceptEPSS 20 %digium · asterisk6 мар. 2007 г.
- CVE-2017-1400137Наблюдать
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior.
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %digium · asterisk gui25 сент. 2017 г.
- CVE-2017-761737Наблюдать
Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %digium · asterisk10 апр. 2017 г.
- CVE-2014-841837Наблюдать
The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and C
КритическаяCVSS 9,0Эксплойта нетEPSS 4 %digium · certified asterisk24 нояб. 2014 г.
- CVE-2011-159937Наблюдать
manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %digium · asterisk26 апр. 2011 г.
- CVE-2017-1667136Наблюдать
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Aster
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %digium · asterisk8 нояб. 2017 г.
- CVE-2022-2649835Наблюдать
An issue was discovered in Asterisk through 19.x.
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %digium · asterisk15 апр. 2022 г.
- CVE-2012-118435Наблюдать
Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows
ВысокаяCVSS 7,5Proof of conceptEPSS 16 %digium · asterisk18 сент. 2012 г.
- CVE-2014-228635Наблюдать
main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x befo
ВысокаяCVSS 7,5Эксплойта нетEPSS 16 %digium · asterisk18 апр. 2014 г.
- CVE-2019-1897634Наблюдать
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x.
ВысокаяCVSS 7,5Эксплойта нетEPSS 13 %digium · asterisk22 нояб. 2019 г.
- CVE-2017-1766433Наблюдать
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified As
СредняяCVSS 5,9Эксплойта нетEPSS 32 %digium · asterisk13 дек. 2017 г.
- CVE-2021-3255833Наблюдать
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certif
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %digium · asterisk30 июл. 2021 г.