Vulnerabilities > Digium > Certified Asterisk > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-02-19 CVE-2021-26713 Out-of-bounds Write vulnerability in Digium Asterisk and Certified Asterisk
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession.
network
low complexity
digium CWE-787
6.5
2021-02-18 CVE-2021-26906 Improper Resource Shutdown or Release vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5.
network
high complexity
digium CWE-404
5.9
2020-11-06 CVE-2020-28327 Improper Resource Shutdown or Release vulnerability in multiple products
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1.
network
high complexity
digium sangoma CWE-404
5.3
2019-11-22 CVE-2019-18790 Missing Authorization vulnerability in multiple products
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5.
network
low complexity
digium debian CWE-862
6.5
2019-07-12 CVE-2019-13161 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3.
network
high complexity
digium debian CWE-476
5.3
2019-07-12 CVE-2019-12827 Out-of-bounds Write vulnerability in Digium Asterisk and Certified Asterisk
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
network
low complexity
digium CWE-787
6.5
2018-06-12 CVE-2018-12227 Information Exposure vulnerability in multiple products
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2.
network
low complexity
digium debian CWE-200
5.3
2018-02-22 CVE-2018-7286 An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2.
network
low complexity
digium debian
6.5
2017-12-13 CVE-2017-17664 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk and Certified Asterisk
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9.
network
high complexity
digium CWE-119
5.9
2017-11-09 CVE-2017-16672 Missing Release of Resource after Effective Lifetime vulnerability in Digium Asterisk
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7.
network
high complexity
digium CWE-772
5.9