İçeriğe atla
Noroxi

asterisk kayıtları

asterisk üreticisine ait 52 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %1,9
Pre-auth RCE
7
Düzeltme kaydı olan
%88,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

52 kayıt
  • CVE-2007-2488
    41Planlayın

    The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trig

    KritikCVSS 10,0İstismar yokEPSS %4

    asterisk · asterisk7 May 2007

  • CVE-2021-37706
    40Planlayın

    Potential integer underflow upon receiving STUN message in PJSIP

    KritikCVSS 9,8İstismar yokEPSS %5

    teluu · pjsip22 Ara 2021

  • CVE-2022-23608
    40Planlayın

    Use after free in PJSIP

    KritikCVSS 9,8İstismar yokEPSS %4

    teluu · pjsip22 Şub 2022

  • CVE-2008-3263
    39İzleyin

    The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.

    YüksekCVSS 7,8Kavram kanıtıEPSS %28

    asterisk · asterisk22 Tem 2008

  • CVE-2007-3762
    39İzleyin

    Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before

    KritikCVSS 9,3İstismar yokEPSS %6

    asterisk · asterisk18 Tem 2007

  • CVE-2008-1390
    38İzleyin

    The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.

    KritikCVSS 9,3İstismar yokEPSS %4

    asterisk · asterisk24 Mar 2008

  • CVE-2007-2293
    37İzleyin

    Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3

    YüksekCVSS 7,6Kavram kanıtıEPSS %24

    asterisk · asterisk26 Nis 2007

  • CVE-2022-21723
    37İzleyin

    Out-of-bounds read in multipart parsing in PJSIP

    KritikCVSS 9,1İstismar yokEPSS %4

    teluu · pjsip26 Oca 2022

  • CVE-2012-2186
    37İzleyin

    Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris

    KritikCVSS 9,0İstismar yokEPSS %4

    asterisk · open source31 Ağu 2012

  • CVE-2024-42365
    36İzleyin

    Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan

    YüksekCVSS 8,8SilahlaştırılmışEPSS %5

    asterisk · asterisk8 Ağu 2024

  • CVE-2008-1332
    36İzleyin

    Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x b

    YüksekCVSS 8,8İstismar yokEPSS %2

    asterisk · asterisk19 Mar 2008

  • CVE-2007-1561
    35İzleyin

    The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP I

    YüksekCVSS 7,8Kavram kanıtıEPSS %14

    asterisk · asterisk21 Mar 2007

  • CVE-2008-1289
    33İzleyin

    Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Editi

    YüksekCVSS 7,5Kavram kanıtıEPSS %12

    asterisk · asterisk appliance developer kit24 Mar 2008

  • CVE-2007-2294
    32İzleyin

    The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using

    YüksekCVSS 7,8İstismar yokEPSS %4

    asterisk · asterisk26 Nis 2007

  • CVE-2008-3264
    32İzleyin

    The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition

    YüksekCVSS 7,8İstismar yokEPSS %3

    asterisk · s800i appliance24 Tem 2008

  • CVE-2007-1594
    32İzleyin

    The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of ser

    YüksekCVSS 7,8İstismar yokEPSS %3

    asterisk · asterisk22 Mar 2007

  • CVE-2009-2346
    32İzleyin

    The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x be

    YüksekCVSS 7,8İstismar yokEPSS %3

    asterisk · asterisk8 Eyl 2009

  • CVE-2007-2297
    32İzleyin

    The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not conta

    YüksekCVSS 7,8İstismar yokEPSS %2

    asterisk · asterisk26 Nis 2007

  • CVE-2017-9358
    31İzleyin

    A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 bef

    YüksekCVSS 7,5İstismar yokEPSS %3

    asterisk · certified asterisk2 Haz 2017

  • CVE-2007-5488
    31İzleyin

    Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    asterisk · asterisk-addons17 Eki 2007

  • CVE-2013-2685
    31İzleyin

    Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbi

    YüksekCVSS 7,5İstismar yokEPSS %3

    asterisk · open source1 Nis 2013

  • CVE-2007-1595
    31İzleyin

    The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to e

    YüksekCVSS 7,5İstismar yokEPSS %3

    asterisk · asterisk22 Mar 2007

  • CVE-2007-3764
    29İzleyin

    The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW befor

    OrtaCVSS 5,0Kavram kanıtıEPSS %32

    asterisk · asterisk18 Tem 2007

  • CVE-2007-3763
    28İzleyin

    The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before be

    OrtaCVSS 5,0Kavram kanıtıEPSS %27

    asterisk · asterisk18 Tem 2007

  • CVE-2008-0095
    28İzleyin

    The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance

    OrtaCVSS 5,0Kavram kanıtıEPSS %25

    asterisk · asterisk appliance developer kit7 Oca 2008