Vulnerabilities > Digium > Asterisk > 15.0.0

DATE CVE VULNERABILITY TITLE RISK
2018-06-12 CVE-2018-12227 Information Exposure vulnerability in multiple products
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2.
network
low complexity
digium debian CWE-200
5.0
2018-02-22 CVE-2018-7287 Improper Check for Unusual or Exceptional Conditions vulnerability in Digium Asterisk
An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1.
network
digium CWE-754
4.3
2018-02-22 CVE-2018-7286 An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2.
network
low complexity
digium debian
4.0
2018-02-22 CVE-2018-7285 NULL Pointer Dereference vulnerability in Digium Asterisk
A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1.
network
low complexity
digium CWE-476
5.0
2018-02-22 CVE-2018-7284 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2.
network
low complexity
digium debian CWE-119
5.0
2017-12-27 CVE-2017-17850 Improper Input Validation vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older.
network
low complexity
digium CWE-20
5.0
2017-12-13 CVE-2017-17664 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk and Certified Asterisk
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9.
network
digium CWE-119
4.3
2017-12-02 CVE-2017-17090 Incomplete Cleanup vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older.
network
low complexity
digium CWE-459
5.0
2017-11-09 CVE-2017-16672 Missing Release of Resource after Effective Lifetime vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7.
network
digium CWE-772
4.3
2017-11-09 CVE-2017-16671 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk and Certified Asterisk
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7.
network
low complexity
digium CWE-119
6.5