Skip to main content

Vendor archive

asterisk CVEs

Beta · best-effort

52 CVEs tagged to vendor asterisk5 Critical, 20 High, 25 Medium, 2 Low, 0 Unrated.

CVE-2013-2685

Published Apr 1, 2013

Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary code via a long sprop-parameter-s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2416

Published Apr 30, 2012

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4, when the trustrpid op…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2415

Published Apr 30, 2012

Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2414

Published Apr 30, 2012

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0885

Published Jan 25, 2012

chan_sip.c in Asterisk Open Source 1.8.x before 1.8.8.2 and 10.x before 10.0.1, when the res_srtp module is used and media support is improperly configured, allows remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4063

Published Oct 21, 2011

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0441

Published Feb 4, 2010

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a deni…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5744

Published Dec 26, 2008

Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by wri…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5396

Published Dec 9, 2008

Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3903

Published Sep 4, 2008

Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 52 CVEsPage 1 of 3