Vulnerabilities > Digium > Certified Asterisk
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-07-12 | CVE-2019-13161 | NULL Pointer Dereference vulnerability in multiple products An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. | 5.3 |
2019-07-12 | CVE-2019-12827 | Out-of-bounds Write vulnerability in Digium Asterisk and Certified Asterisk Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message. | 6.5 |
2018-09-24 | CVE-2018-17281 | Resource Exhaustion vulnerability in multiple products There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. | 7.5 |
2018-06-12 | CVE-2018-12227 | Information Exposure vulnerability in multiple products An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. | 5.3 |
2018-02-22 | CVE-2018-7286 | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. | 6.5 |
2018-02-22 | CVE-2018-7284 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. | 7.5 |
2017-12-27 | CVE-2017-17850 | Improper Input Validation vulnerability in Digium Asterisk and Certified Asterisk An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. | 7.5 |
2017-12-13 | CVE-2017-17664 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk and Certified Asterisk A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. | 5.9 |
2017-12-02 | CVE-2017-17090 | Incomplete Cleanup vulnerability in Digium Certified Asterisk An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. | 7.5 |
2017-11-09 | CVE-2017-16672 | Missing Release of Resource after Effective Lifetime vulnerability in Digium Asterisk An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. | 5.9 |