Vulnerabilities > Digium > Asterisk > 1.4.4

DATE CVE VULNERABILITY TITLE RISK
2007-10-12 CVE-2007-5358 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Digium Asterisk
Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields.
network
digium CWE-119
6.8
2007-07-31 CVE-2007-4103 Missing Release of Resource after Effective Lifetime vulnerability in Digium Asterisk and Asterisk Appliance Developer KIT
The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and Asterisk Appliance Developer Kit before 0.6.0, when configured to allow unauthenticated calls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of calls that do not complete a 3-way handshake, which causes an ast_channel to be allocated but not released.
network
low complexity
digium CWE-772
7.5