Skip to main content

Vendor archive

digium CVEs

Beta · best-effort

119 CVEs tagged to vendor digium5 Critical, 40 High, 69 Medium, 5 Low, 0 Unrated.

CVE-2012-5976

Published Jan 4, 2013

Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1184

Published Sep 18, 2012

Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1183

Published Sep 18, 2012

Stack-based buffer overflow in the milliwatt_generate function in the Miliwatt application in Asterisk 1.4.x before 1.4.44, 1.6.x before 1.6.2.23, 1.8.x before 1.8.10.1, and 10.x…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4737

Published Aug 31, 2012

channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Digiumphones 10.x.x-digiumphones…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3553

Published Jun 19, 2012

chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer deref…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4598

Published Dec 15, 2011

The handle_request_info function in channels/chan_sip.c in Asterisk Open Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is enabled, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4597

Published Dec 15, 2011

The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2666

Published Jul 6, 2011

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2665

Published Jul 6, 2011

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.3 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2536

Published Jul 6, 2011

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2535

Published Jul 6, 2011

chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asterisk Business Edition C.3 before…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2529

Published Jul 6, 2011

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2216

Published Jun 6, 2011

reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.2 does not initialize certain strings, which allows remote attackers to cause a denial of ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1599

Published Apr 27, 2011

manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Busines…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1507

Published Apr 27, 2011

Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1175

Published Mar 31, 2011

tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1.x before 1.6.1.23, 1.6.2.x before 1.6.2.17.1, and 1.8.x before 1.8.3.1 allows remote attackers to cause a denial of se…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1174

Published Mar 31, 2011

manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a denial of service (CPU and memory…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1224

Published Apr 1, 2010

main/acl.c in Asterisk Open Source 1.6.0.x before 1.6.0.25, 1.6.1.x before 1.6.1.17, and 1.6.2.x before 1.6.2.5 does not properly enforce remote host access controls when CIDR not…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0685

Published Feb 23, 2010

The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using the ${EXTEN} channel variable a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4055

Published Dec 2, 2009

rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition B.x.x before B.2.5.13, C.2.x.x bef…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 119 CVEsPage 4 of 5