Vulnerabilities > Digium > Asterisk > 15.1.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-14 | CVE-2023-37457 | Classic Buffer Overflow vulnerability in multiple products Asterisk is an open source private branch exchange and telephony toolkit. | 8.2 |
2023-12-14 | CVE-2023-49294 | Asterisk is an open source private branch exchange and telephony toolkit. | 7.5 |
2023-12-14 | CVE-2023-49786 | Race Condition vulnerability in multiple products Asterisk is an open source private branch exchange and telephony toolkit. | 5.9 |
2021-01-29 | CVE-2020-35652 | Unspecified vulnerability in Digium Asterisk An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. | 6.5 |
2019-09-09 | CVE-2019-15297 | NULL Pointer Dereference vulnerability in Digium Asterisk res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. | 6.5 |
2019-07-12 | CVE-2019-13161 | NULL Pointer Dereference vulnerability in multiple products An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. | 5.3 |
2019-07-12 | CVE-2019-12827 | Out-of-bounds Write vulnerability in Digium Asterisk and Certified Asterisk Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message. | 6.5 |
2019-03-28 | CVE-2019-7251 | Integer Overflow or Wraparound vulnerability in Digium Asterisk An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation. | 6.5 |
2018-11-14 | CVE-2018-19278 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length. | 7.5 |
2018-06-12 | CVE-2018-12227 | Information Exposure vulnerability in multiple products An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. | 5.3 |