Skip to main content

Vendor archive

digium CVEs

Beta · best-effort

119 CVEs tagged to vendor digium5 Critical, 40 High, 69 Medium, 5 Low, 0 Unrated.

CVE-2016-2232

Published Feb 22, 2016

Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3008

Published Apr 10, 2015

Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1558

Published Feb 9, 2015

Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-9374

Published Dec 12, 2014

Double free vulnerability in the WebSocket Server (res_http_websocket module) in Asterisk Open Source 11.x before 11.14.2, 12.x before 12.7.2, and 13.x before 13.0.2 and Certified…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6610

Published Nov 26, 2014

Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated u…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6609

Published Nov 26, 2014

The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIB…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8418

Published Nov 24, 2014

The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cer…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8417

Published Nov 24, 2014

ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote authenticated users to (1) gain…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8416

Published Nov 24, 2014

Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_refer module, allows remote at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8415

Published Nov 24, 2014

Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a denial of service (assertion f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8414

Published Nov 24, 2014

ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote attackers to cause a denial of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8413

Published Nov 24, 2014

The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and load ACLs defined in pjsip.conf at startup, which allows re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8412

Published Nov 24, 2014

The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1, 12.x before 12.7.1, and 13.x…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4048

Published Jun 17, 2014

The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (deadlock) by terminating a subscription request before it is c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4047

Published Jun 17, 2014

Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4046

Published Jun 17, 2014

Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4045

Published Jun 17, 2014

The Publish/Subscribe Framework in the PJSIP channel driver in Asterisk Open Source 12.x before 12.3.1, when sub_min_expiry is set to zero, allows remote attackers to cause a deni…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2289

Published Apr 18, 2014

res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUB…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2288

Published Apr 18, 2014

The PJSIP channel driver in Asterisk Open Source 12.x before 12.1.1, when qualify_frequency "is enabled on an AOR and the remote SIP server challenges for authentication of the re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5641

Published Sep 9, 2013

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.17.x through 1.8.22.x, 1.8.23.x before 1.8.23.1, and 11.x before 11.5.1 and Certified Asterisk 1.8.15 befo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5977

Published Jan 4, 2013

Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphone…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 119 CVEsPage 3 of 5