Products: 12
    Vulnerabilities: 119
    Known Exploited: 0
    5
    Critical Level Threats
    40
    High Level Threats
    69
    Medium Level Threats
    5
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-49786

    Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation

    Last Modified: Feb 13, 2025
    Published: Dec 14, 2023

    CVE-2023-37457

    Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update'

    Last Modified: Feb 13, 2025
    Published: Dec 14, 2023

    CVE-2023-49294

    Asterisk Path Traversal vulnerability

    Last Modified: Feb 13, 2025
    Published: Dec 14, 2023

    CVE-2021-46837

    res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port in a response to a T.38 re-invite initiated by Asterisk. This is a re-occurrence of the CVE-2019-15297 symptoms but not for exactly the same reason. The crash occurs because there is an append operation relative to the active topology, but this should instead be a replace operation.

    Last Modified: Nov 21, 2024
    Published: Aug 30, 2022

    CVE-2022-26498

    An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

    Last Modified: Nov 21, 2024
    Published: Apr 15, 2022
    Items Per Page