Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 4.2% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/11/2019 | 17/6/2026 | An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a… | |
| Modificada | Alta (7.5) | 1.2% | — | Sangoma AsteriskDebian Linux | 29/10/2019 | 16/6/2026 | asterisk allows calls on prohibited networks | |
| Modificada | Media (6.5) | 3.4% | — | Digium Asterisk | 9/9/2019 | 17/6/2026 | res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference. | |
| Modificada | Alta (7.5) | 22% | — | Digium Asterisk | 9/9/2019 | 17/6/2026 | main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario. | |
| Modificada | Media (5.3) | 4.0% | — | Digium Certified AsteriskDigium AsteriskDebian Linux | 12/7/2019 | 17/6/2026 | An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38… | |
| Modificada | Media (6.5) | 4.1% | — | Digium AsteriskDigium Certified Asterisk | 12/7/2019 | 17/6/2026 | Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message. | |
| Modificada | Alta (7.5) | 2.0% | — | Digium Asterisk | 23/5/2019 | 17/6/2026 | asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote). | |
| Modificada | Media (6.5) | 3.6% | — | Digium Asterisk | 28/3/2019 | 17/6/2026 | An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asterisk via a specially crafted SDP protocol violation. | |
| Modificada | Alta (7.5) | 3.6% | — | Digium Asterisk | 14/11/2018 | 17/6/2026 | Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length. | |
| Modificada | Alta (7.5) | 52% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 24/9/2018 | 17/6/2026 | There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket. | |
| Modificada | Media (6.5) | 6.7% | — | Sangoma Asterisk | 12/6/2018 | 17/6/2026 | An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infinite loop while trying to read the data stream. This renders the system unusable. | |
| Modificada | Media (5.3) | 3.5% | — | Digium AsteriskDigium Certified AsteriskDebian Linux | 12/6/2018 | 17/6/2026 | An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP request, they respond with a 403 forbidden. However, if an endpoint is not… | |
| Modificada | Media (5.9) | 11% | — | Digium Asterisk | 22/2/2018 | 17/6/2026 | An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop). | |
| Modificada | Media (6.5) | 53% | 💥 Exploit | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/2/2018 | 17/6/2026 | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly… | |
| Modificada | Alta (7.5) | 5.0% | — | Digium Asterisk | 22/2/2018 | 17/6/2026 | A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs and desired payload numbers. While an SDP negotiation may result in a codec using a different payload number, these desired ones are still stored internally. When an RTP… | |
| Modificada | Alta (7.5) | 66% | 💥 Exploit | Digium AsteriskDigium Certified AsteriskDebian Linux | 22/2/2018 | 17/6/2026 | A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not… | |
| Modificada | Alta (7.5) | 75% | — | Digium AsteriskDigium Certified Asterisk | 27/12/2017 | 17/6/2026 | An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and the PJSIP channel driver was used,… | |
| Modificada | Media (5.9) | 32% | — | Digium AsteriskDigium Certified Asterisk | 13/12/2017 | 17/6/2026 | A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack. | |
| Modificada | Alta (7.5) | 82% | 💥 Exploit | Digium Certified AsteriskDigium Asterisk | 2/12/2017 | 17/6/2026 | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of… | |
| Modificada | Media (5.9) | 4.7% | — | Digium AsteriskDigium Certified Asterisk | 9/11/2017 | 17/6/2026 | An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected before the session itself is fully established. When this happens… | |
| Modificada | Alta (8.8) | 3.3% | — | Digium AsteriskDigium Certified Asterisk | 9/11/2017 | 17/6/2026 | A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and… | |
| Modificada | Alta (7.5) | 3.2% | — | Digium AsteriskDigium Certified Asterisk | 10/10/2017 | 17/6/2026 | In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with the "nat" and "symmetric_rtp" options allow redirecting where… | |
| Modificada | Alta (8.8) | 6.4% | — | Digium Asterisk GUI | 26/9/2017 | 17/6/2026 | An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injection vulnerability has been identified that may allow the execution of arbitrary code on the system through the inclusion of OS commands in the URL request of the program. | |
| Modificada | Crítica (9.8) | 15% | — | Digium AsteriskDigium Certified Asterisk | 2/9/2017 | 17/6/2026 | In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is executed by the MinivmNotify dialplan… | |
| Modificada | Alta (7.5) | 4.3% | — | Digium AsteriskDigium Certified Asterisk | 2/9/2017 | 17/6/2026 | In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The "strictrtp" option in… |