Vulnerabilities > Digium > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-14 CVE-2018-19278 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.
network
low complexity
digium CWE-119
7.5
2018-09-24 CVE-2018-17281 Resource Exhaustion vulnerability in multiple products
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2.
network
low complexity
digium debian CWE-400
7.5
2018-02-22 CVE-2018-7285 NULL Pointer Dereference vulnerability in Digium Asterisk
A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1.
network
low complexity
digium CWE-476
7.5
2018-02-22 CVE-2018-7284 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2.
network
low complexity
digium debian CWE-119
7.5
2017-12-27 CVE-2017-17850 Improper Input Validation vulnerability in Digium Asterisk and Certified Asterisk
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older.
network
low complexity
digium CWE-20
7.5
2017-12-02 CVE-2017-17090 Incomplete Cleanup vulnerability in Digium Certified Asterisk
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older.
network
low complexity
digium CWE-459
7.5
2017-11-09 CVE-2017-16671 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digium Asterisk
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7.
network
low complexity
digium CWE-119
8.8
2017-10-10 CVE-2017-14603 Information Exposure vulnerability in Digium Asterisk
In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with the "nat" and "symmetric_rtp" options allow redirecting where Asterisk sends the next RTCP report.
network
low complexity
digium CWE-200
7.5
2017-09-26 CVE-2017-14001 OS Command Injection vulnerability in Digium Asterisk GUI 2.1.0
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior.
network
low complexity
digium CWE-78
8.8
2017-09-02 CVE-2017-14099 Information Exposure vulnerability in Digium Asterisk
In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker.
network
low complexity
digium CWE-200
7.5