Search CVE reports


Toggle filters

11 – 20 of 189 results


CVE-2024-57520

Medium priority
Needs evaluation

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-53566

Medium priority
Needs evaluation

An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-49215

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-49294. Reason: This candidate is a reservation duplicate of CVE-2023-49294. Notes: All CVE users should reference CVE-2023-49294 instead of this candidate....

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-42491

Medium priority
Needs evaluation

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-42365

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate`...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-35190

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1,...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-49786

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-49294

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-37457

Medium priority
Needs evaluation

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-38703

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level...

2 affected packages

asterisk, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ring Not in release Not in release Needs evaluation Needs evaluation
Show less packages