Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | Digium AsteriskDigium Certified Asterisk | 18/2/2021 | 17/6/2026 | An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the… | |
| Modificada | Media (5.3) | 1.9% | — | Digium Certified AsteriskSangoma Asterisk | 6/11/2020 | 17/6/2026 | A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return the created dialog locked or referenced. This caused a gap between… | |
| Modificada | Media (6.5) | 1.5% | — | Certified AsteriskSangoma AsteriskFedoraproject FedoraDebian Linux | 6/11/2020 | 17/6/2026 | An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop.… | |
| Modificada | Alta (8.8) | 50% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/11/2019 | 17/6/2026 | An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands. | |
| Modificada | Alta (7.5) | 13% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/11/2019 | 17/6/2026 | An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940. | |
| Modificada | Media (6.5) | 4.2% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/11/2019 | 17/6/2026 | An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a… | |
| Modificada | Media (5.3) | 4.0% | — | Digium Certified AsteriskDigium AsteriskDebian Linux | 12/7/2019 | 17/6/2026 | An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38… | |
| Modificada | Media (6.5) | 4.1% | — | Digium AsteriskDigium Certified Asterisk | 12/7/2019 | 17/6/2026 | Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message. | |
| Modificada | Alta (7.5) | 52% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 24/9/2018 | 17/6/2026 | There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket. | |
| Modificada | Media (5.3) | 3.5% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 12/6/2018 | 17/6/2026 | An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP request, they respond with a 403 forbidden. However, if an endpoint is not… | |
| Modificada | Media (6.5) | 53% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/2/2018 | 17/6/2026 | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly… | |
| Modificada | Alta (7.5) | 66% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/2/2018 | 17/6/2026 | A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not… | |
| Modificada | Alta (7.5) | 75% | — | Digium AsteriskDigium Certified Asterisk | 27/12/2017 | 17/6/2026 | An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and the PJSIP channel driver was used,… | |
| Modificada | Media (5.9) | 32% | — | Digium AsteriskDigium Certified Asterisk | 13/12/2017 | 17/6/2026 | A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack. | |
| Modificada | Alta (7.5) | 82% | — | Digium Certified AsteriskDigium Asterisk | 2/12/2017 | 17/6/2026 | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of… | |
| Modificada | Media (5.9) | 4.7% | — | Digium AsteriskDigium Certified Asterisk | 9/11/2017 | 17/6/2026 | An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected before the session itself is fully established. When this happens… | |
| Modificada | Alta (8.8) | 3.3% | — | Digium AsteriskDigium Certified Asterisk | 9/11/2017 | 17/6/2026 | A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and… | |
| Modificada | Alta (7.5) | 3.2% | — | Digium AsteriskDigium Certified Asterisk | 10/10/2017 | 17/6/2026 | In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with the "nat" and "symmetric_rtp" options allow redirecting where… | |
| Modificada | Crítica (9.8) | 15% | — | Digium AsteriskDigium Certified Asterisk | 2/9/2017 | 17/6/2026 | In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is executed by the MinivmNotify dialplan… | |
| Modificada | Alta (7.5) | 4.3% | — | Digium AsteriskDigium Certified Asterisk | 2/9/2017 | 17/6/2026 | In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The "strictrtp" option in… | |
| Modificada | Alta (7.5) | 4.0% | — | Digium Open SourceDigium Certified Asterisk | 2/6/2017 | 17/6/2026 | PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (buffer overflow and application crash) via a SIP packet with a crafted CSeq header in conjunction with a Via header… | |
| Modificada | Alta (7.5) | 3.8% | — | Digium Open SourceDigium Certified Asterisk | 2/6/2017 | 17/6/2026 | The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet. | |
| Modificada | Alta (7.5) | 2.7% | — | Sangoma AsteriskCertified Asterisk | 2/6/2017 | 17/6/2026 | A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop). | |
| Modificada | Alta (7.5) | 5.3% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 17/4/2017 | 17/6/2026 | chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion). | |
| Modificada | Alta (8.8) | 6.2% | — | Digium AsteriskDigium Certified Asterisk | 10/4/2017 | 17/6/2026 | Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action. |