Vulnerabilities > Digium > Asterisk > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-49786 Race Condition vulnerability in multiple products
Asterisk is an open source private branch exchange and telephony toolkit.
network
high complexity
sangoma digium CWE-362
5.9
2022-08-30 CVE-2021-46837 NULL Pointer Dereference vulnerability in multiple products
res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port in a response to a T.38 re-invite initiated by Asterisk.
network
low complexity
asterisk digium debian CWE-476
6.5
2021-07-30 CVE-2021-31878 Reachable Assertion vulnerability in Digium Asterisk
An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1.
network
low complexity
digium CWE-617
6.5
2021-02-19 CVE-2021-26713 Out-of-bounds Write vulnerability in Digium Asterisk and Certified Asterisk
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession.
network
low complexity
digium CWE-787
6.5
2021-02-18 CVE-2021-26906 Improper Resource Shutdown or Release vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5.
network
high complexity
digium CWE-404
5.9
2021-02-18 CVE-2020-35776 Classic Buffer Overflow vulnerability in Digium Asterisk
A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.
network
low complexity
digium CWE-120
6.5
2021-01-29 CVE-2020-35652 Unspecified vulnerability in Digium Asterisk
An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0.
network
low complexity
digium
6.5
2019-11-22 CVE-2019-18790 Missing Authorization vulnerability in multiple products
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5.
network
low complexity
digium debian CWE-862
6.5
2019-09-09 CVE-2019-15297 NULL Pointer Dereference vulnerability in Digium Asterisk
res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk.
network
low complexity
digium CWE-476
6.5
2019-07-12 CVE-2019-13161 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3.
network
high complexity
digium debian CWE-476
5.3