Vulnerabilities > Digium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-15 | CVE-2022-26498 | Resource Exhaustion vulnerability in Digium Asterisk An issue was discovered in Asterisk through 19.x. | 5.0 |
2022-04-15 | CVE-2022-26499 | Server-Side Request Forgery (SSRF) vulnerability in Digium Asterisk An SSRF issue was discovered in Asterisk through 19.x. | 6.4 |
2022-04-15 | CVE-2022-26651 | SQL Injection vulnerability in Digium Asterisk and Certified Asterisk An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. | 7.5 |
2021-07-30 | CVE-2021-31878 | Reachable Assertion vulnerability in Digium Asterisk An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. | 4.0 |
2021-07-30 | CVE-2021-32558 | Injection vulnerability in multiple products An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. | 5.0 |
2021-03-05 | CVE-2019-18351 | Incorrect Permission Assignment for Critical Resource vulnerability in Digium Asterisk An issue was discovered in channels/chan_sip.c in Sangoma Asterisk through 13.29.1, through 16.6.1, and through 17.0.0; and Certified Asterisk through 13.21-cert4. | 4.0 |
2021-02-19 | CVE-2021-26713 | Out-of-bounds Write vulnerability in Digium Asterisk and Certified Asterisk A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession. | 4.0 |
2021-02-18 | CVE-2021-26712 | Unspecified vulnerability in Digium Asterisk Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replaying SRTP packets. | 5.0 |
2021-02-18 | CVE-2021-26906 | Improper Resource Shutdown or Release vulnerability in Digium Asterisk An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. | 4.3 |
2021-02-18 | CVE-2021-26717 | Unspecified vulnerability in Digium Asterisk and Certified Asterisk An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. | 5.0 |