Vulnerabilities > Digium

DATE CVE VULNERABILITY TITLE RISK
2022-04-15 CVE-2022-26498 Resource Exhaustion vulnerability in Digium Asterisk
An issue was discovered in Asterisk through 19.x.
network
low complexity
digium CWE-400
5.0
2022-04-15 CVE-2022-26499 Server-Side Request Forgery (SSRF) vulnerability in Digium Asterisk
An SSRF issue was discovered in Asterisk through 19.x.
network
low complexity
digium CWE-918
6.4
2022-04-15 CVE-2022-26651 SQL Injection vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13.
network
low complexity
digium CWE-89
7.5
2021-07-30 CVE-2021-31878 Reachable Assertion vulnerability in Digium Asterisk
An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1.
network
low complexity
digium CWE-617
4.0
2021-07-30 CVE-2021-32558 Injection vulnerability in multiple products
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10.
network
low complexity
digium debian CWE-74
5.0
2021-03-05 CVE-2019-18351 Incorrect Permission Assignment for Critical Resource vulnerability in Digium Asterisk
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk through 13.29.1, through 16.6.1, and through 17.0.0; and Certified Asterisk through 13.21-cert4.
network
high complexity
digium CWE-732
4.0
2021-02-19 CVE-2021-26713 Out-of-bounds Write vulnerability in Digium Asterisk and Certified Asterisk
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession.
network
low complexity
digium CWE-787
4.0
2021-02-18 CVE-2021-26712 Unspecified vulnerability in Digium Asterisk
Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replaying SRTP packets.
network
low complexity
digium
5.0
2021-02-18 CVE-2021-26906 Improper Resource Shutdown or Release vulnerability in Digium Asterisk
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5.
network
digium CWE-404
4.3
2021-02-18 CVE-2021-26717 Unspecified vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6.
network
low complexity
digium
5.0