asterisk kayıtları
asterisk üreticisine ait 52 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %1,9
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %88,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-287 Improper Authentication5
- CWE-399 Resource Management Errors4
- CWE-20 Improper Input Validation3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-189 Numeric Errors2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
52 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2007-2488İstismar yok | The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigasterisk · asterisk | Kritik10,0 | — | %4,3 | 7 May 2007 |
40Planlayın | CVE-2021-37706İstismar yok | Potential integer underflow upon receiving STUN message in PJSIPteluu · pjsip · CWE-191 | Kritik9,8 | — | %4,6 | 22 Ara 2021 |
40Planlayın | CVE-2022-23608İstismar yok | Use after free in PJSIPteluu · pjsip · CWE-416 | Kritik9,8 | — | %4,0 | 22 Şub 2022 |
39İzleyin | CVE-2008-3263Kavram kanıtı | The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.asterisk · asterisk · CWE-399 | Yüksek7,8 | — | %28,0 | 22 Tem 2008 |
39İzleyin | CVE-2007-3762İstismar yok | Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition beforeasterisk · asterisk | Kritik9,3 | — | %5,5 | 18 Tem 2007 |
38İzleyin | CVE-2008-1390İstismar yok | The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.asterisk · asterisk · CWE-255 | Kritik9,3 | — | %3,8 | 24 Mar 2008 |
37İzleyin | CVE-2007-2293Kavram kanıtı | Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 asterisk · asterisk | Yüksek7,6 | — | %23,9 | 26 Nis 2007 |
37İzleyin | CVE-2022-21723İstismar yok | Out-of-bounds read in multipart parsing in PJSIPteluu · pjsip · CWE-125 | Kritik9,1 | — | %4,4 | 26 Oca 2022 |
37İzleyin | CVE-2012-2186İstismar yok | Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisasterisk · open source | Kritik9,0 | — | %3,6 | 31 Ağu 2012 |
36İzleyin | CVE-2024-42365Silahlaştırılmış | Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplanasterisk · asterisk · CWE-267 | Yüksek8,8 | — | %4,7 | 8 Ağu 2024 |
36İzleyin | CVE-2008-1332İstismar yok | Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x basterisk · asterisk · CWE-264 | Yüksek8,8 | — | %2,3 | 19 Mar 2008 |
35İzleyin | CVE-2007-1561Kavram kanıtı | The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Iasterisk · asterisk | Yüksek7,8 | — | %14,5 | 21 Mar 2007 |
33İzleyin | CVE-2008-1289Kavram kanıtı | Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editiasterisk · asterisk appliance developer kit · CWE-119 | Yüksek7,5 | — | %11,5 | 24 Mar 2008 |
32İzleyin | CVE-2007-2294İstismar yok | The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by usingasterisk · asterisk | Yüksek7,8 | — | %3,9 | 26 Nis 2007 |
32İzleyin | CVE-2008-3264İstismar yok | The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Editionasterisk · s800i appliance · CWE-287 | Yüksek7,8 | — | %3,4 | 24 Tem 2008 |
32İzleyin | CVE-2007-1594İstismar yok | The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of serasterisk · asterisk | Yüksek7,8 | — | %2,6 | 22 Mar 2007 |
32İzleyin | CVE-2009-2346İstismar yok | The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x beasterisk · asterisk · CWE-119 | Yüksek7,8 | — | %2,6 | 8 Eyl 2009 |
32İzleyin | CVE-2007-2297İstismar yok | The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contaasterisk · asterisk | Yüksek7,8 | — | %2,4 | 26 Nis 2007 |
31İzleyin | CVE-2017-9358İstismar yok | A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 befasterisk · certified asterisk · CWE-835 | Yüksek7,5 | — | %2,7 | 2 Haz 2017 |
31İzleyin | CVE-2007-5488Kavram kanıtı | Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers toasterisk · asterisk-addons · CWE-89 | Yüksek7,5 | — | %2,7 | 17 Eki 2007 |
31İzleyin | CVE-2013-2685İstismar yok | Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbiasterisk · open source · CWE-119 | Yüksek7,5 | — | %2,6 | 1 Nis 2013 |
31İzleyin | CVE-2007-1595İstismar yok | The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to easterisk · asterisk | Yüksek7,5 | — | %2,6 | 22 Mar 2007 |
29İzleyin | CVE-2007-3764Kavram kanıtı | The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW beforasterisk · asterisk | Orta5,0 | — | %31,5 | 18 Tem 2007 |
28İzleyin | CVE-2007-3763Kavram kanıtı | The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beasterisk · asterisk | Orta5,0 | — | %26,6 | 18 Tem 2007 |
28İzleyin | CVE-2008-0095Kavram kanıtı | The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Applianceasterisk · asterisk appliance developer kit · CWE-399 | Orta5,0 | — | %25,4 | 7 Oca 2008 |
- CVE-2007-248841Planlayın
The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trig
KritikCVSS 10,0İstismar yokEPSS %4asterisk · asterisk7 May 2007
- CVE-2021-3770640Planlayın
Potential integer underflow upon receiving STUN message in PJSIP
KritikCVSS 9,8İstismar yokEPSS %5teluu · pjsip22 Ara 2021
- CVE-2022-2360840Planlayın
Use after free in PJSIP
KritikCVSS 9,8İstismar yokEPSS %4teluu · pjsip22 Şub 2022
- CVE-2008-326339İzleyin
The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.
YüksekCVSS 7,8Kavram kanıtıEPSS %28asterisk · asterisk22 Tem 2008
- CVE-2007-376239İzleyin
Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before
KritikCVSS 9,3İstismar yokEPSS %6asterisk · asterisk18 Tem 2007
- CVE-2008-139038İzleyin
The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.
KritikCVSS 9,3İstismar yokEPSS %4asterisk · asterisk24 Mar 2008
- CVE-2007-229337İzleyin
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3
YüksekCVSS 7,6Kavram kanıtıEPSS %24asterisk · asterisk26 Nis 2007
- CVE-2022-2172337İzleyin
Out-of-bounds read in multipart parsing in PJSIP
KritikCVSS 9,1İstismar yokEPSS %4teluu · pjsip26 Oca 2022
- CVE-2012-218637İzleyin
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris
KritikCVSS 9,0İstismar yokEPSS %4asterisk · open source31 Ağu 2012
- CVE-2024-4236536İzleyin
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
YüksekCVSS 8,8SilahlaştırılmışEPSS %5asterisk · asterisk8 Ağu 2024
- CVE-2008-133236İzleyin
Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x b
YüksekCVSS 8,8İstismar yokEPSS %2asterisk · asterisk19 Mar 2008
- CVE-2007-156135İzleyin
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP I
YüksekCVSS 7,8Kavram kanıtıEPSS %14asterisk · asterisk21 Mar 2007
- CVE-2008-128933İzleyin
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editi
YüksekCVSS 7,5Kavram kanıtıEPSS %12asterisk · asterisk appliance developer kit24 Mar 2008
- CVE-2007-229432İzleyin
The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using
YüksekCVSS 7,8İstismar yokEPSS %4asterisk · asterisk26 Nis 2007
- CVE-2008-326432İzleyin
The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition
YüksekCVSS 7,8İstismar yokEPSS %3asterisk · s800i appliance24 Tem 2008
- CVE-2007-159432İzleyin
The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of ser
YüksekCVSS 7,8İstismar yokEPSS %3asterisk · asterisk22 Mar 2007
- CVE-2009-234632İzleyin
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x be
YüksekCVSS 7,8İstismar yokEPSS %3asterisk · asterisk8 Eyl 2009
- CVE-2007-229732İzleyin
The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not conta
YüksekCVSS 7,8İstismar yokEPSS %2asterisk · asterisk26 Nis 2007
- CVE-2017-935831İzleyin
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 bef
YüksekCVSS 7,5İstismar yokEPSS %3asterisk · certified asterisk2 Haz 2017
- CVE-2007-548831İzleyin
Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %3asterisk · asterisk-addons17 Eki 2007
- CVE-2013-268531İzleyin
Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbi
YüksekCVSS 7,5İstismar yokEPSS %3asterisk · open source1 Nis 2013
- CVE-2007-159531İzleyin
The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to e
YüksekCVSS 7,5İstismar yokEPSS %3asterisk · asterisk22 Mar 2007
- CVE-2007-376429İzleyin
The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW befor
OrtaCVSS 5,0Kavram kanıtıEPSS %32asterisk · asterisk18 Tem 2007
- CVE-2007-376328İzleyin
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before be
OrtaCVSS 5,0Kavram kanıtıEPSS %27asterisk · asterisk18 Tem 2007
- CVE-2008-009528İzleyin
The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance
OrtaCVSS 5,0Kavram kanıtıEPSS %25asterisk · asterisk appliance developer kit7 Oca 2008