Search CVE reports


Toggle filters

71 – 80 of 189 results


CVE-2017-16671

High priority

Some fixes available 1 of 3

A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected
Show less packages

CVE-2017-14603

Medium priority
Vulnerable

In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-14100

Medium priority
Vulnerable

In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-14099

Low priority
Vulnerable

In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-14098

Medium priority
Vulnerable

In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-9358

Medium priority
Vulnerable

A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7551

Medium priority
Vulnerable

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-7617

Medium priority

Some fixes available 1 of 5

Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected
Show less packages

CVE-2016-9938

Low priority
Vulnerable

An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.8-cert4. The chan_sip channel driver has a liberal...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-9937

Medium priority
Not affected

An issue was discovered in Asterisk Open Source 13.12.x and 13.13.x before 13.13.1 and 14.x before 14.2.1. If an SDP offer or answer is received with the Opus codec and with the format parameters separated using a space the code...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk
Show less packages