Vulnerabilities > Digium

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-28327 Improper Resource Shutdown OR Release vulnerability in multiple products
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1.
network
high complexity
asterisk digium CWE-404
2.1
2019-11-22 CVE-2019-18610 Missing Authorization vulnerability in multiple products
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4.
network
low complexity
digium debian CWE-862
critical
9.0
2019-11-22 CVE-2019-18976 Null Pointer Dereference vulnerability in Digium Asterisk
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x.
network
low complexity
digium CWE-476
5.0
2019-11-22 CVE-2019-18790 Missing Authorization vulnerability in multiple products
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x, 16.x, and 17.x, and Certified Asterisk 13.21, because of an incomplete fix for CVE-2019-18351.
5.8
2019-09-09 CVE-2019-15297 Null Pointer Dereference vulnerability in Digium Asterisk
res_pjsip_t38 in Sangoma Asterisk 13.21-cert4, 15.7.3, and 16.5.0 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk.
network
low complexity
digium CWE-476
4.0
2019-09-09 CVE-2019-15639 Improper Input Validation vulnerability in Digium Asterisk
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.
network
low complexity
digium CWE-20
5.0
2019-07-12 CVE-2019-13161 Null Pointer Dereference vulnerability in Digium Certified Asterisk
An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3.
network
digium CWE-476
3.5
2019-07-12 CVE-2019-12827 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Digium Asterisk and Certified Asterisk
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
network
low complexity
digium CWE-119
4.0
2019-05-23 CVE-2016-7550 Null Pointer Dereference vulnerability in Digium Asterisk 13.10.0
asterisk 13.10.0 is affected by: denial of service issues in asterisk.
network
low complexity
digium CWE-476
5.0
2019-03-28 CVE-2019-7251 Integer Overflow OR Wraparound vulnerability in Digium Asterisk
An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation.
network
low complexity
digium CWE-190
4.0