Vulnerabilities > Digium > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-12-02 CVE-2009-4055 Remote Denial of Service vulnerability in Digium Asterisk and S800I
rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition B.x.x before B.2.5.13, C.2.x.x before C.2.4.6, and C.3.x.x before C.3.2.3; and s800i 1.3.x before 1.3.0.6 allows remote attackers to cause a denial of service (daemon crash) via an RTP comfort noise payload with a long data length.
network
low complexity
digium
5.0
2009-11-10 CVE-2009-3727 Information Exposure vulnerability in Digium Asterisk, Asterisknow and S800I
Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2; AsteriskNOW 1.5; and s800i 1.3.x before 1.3.0.5 generate different error messages depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames via multiple crafted REGISTER messages with inconsistent usernames in the URI in the To header and the Digest in the Authorization header.
network
low complexity
digium CWE-200
5.0
2009-07-30 CVE-2009-2651 Resource Management Errors vulnerability in Digium Asterisk 1.6.1
main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a certain delimiter, which triggers a NULL pointer dereference and the subsequent calculation of an invalid pointer.
network
low complexity
digium CWE-399
5.0
2007-11-30 CVE-2007-6170 SQL Injection vulnerability in multiple products
SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments.
network
low complexity
digium debian CWE-89
6.5
2007-10-12 CVE-2007-5358 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Digium Asterisk
Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields.
network
digium CWE-119
6.8
2006-04-18 CVE-2006-1827 Integer Overflow vulnerability in Asterisk JPEG File Handling
Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned length.
network
low complexity
digium
6.4
2005-11-16 CVE-2005-3559 Unspecified vulnerability in Digium Asterisk
Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a ..
network
low complexity
digium
5.0
2005-07-05 CVE-2005-2081 Unspecified vulnerability in Digium Asterisk 1.0.7
Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.
network
low complexity
digium
5.0